In this article

Iran's APTs and the U.S. Enterprise in 2026: A Strategic Shift You Can No Longer Outrun

Post 1 of 5. Series introduction. How four state-aligned threat groups (MuddyWater, APT42, Prince of Persia, and APT34) moved from regional espionage to hybrid operations, and why their 2025-26 campaigns already include named US victims.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Published July 22, 2026

Iran APT

In February 2026, an Iranian state-aligned threat group reportedly deployed a previously undocumented JavaScript-runtime backdoor against U.S. banking and finance entities, a major U.S. airport, and the Israeli operations of a U.S.-based software company. The intrusions intensified through March, coinciding with what public reporting describes as heightened geopolitical tensions in the Middle East.

Data exfiltration ran through Rclone to Wasabi cloud storage - legitimate tooling, routine traffic.

That group is MuddyWater. The backdoor is Dindoor. And the campaign is one of four Iranian state-sponsored operations against U.S.-relevant targets that KELA's Cyber Intelligence Center (CIC) research team has tracked into the current quarter.

This post opens a five-part series examining the four most consequential Iranian APT groups currently active: MuddyWater, APT42, Prince of Persia, and APT34. They all have multiple aliases as we’ll dig into.

The series is written for U.S.-based security leaders and the threat research teams who advise them, but applies globally as a reference, and is built on KELA's intelligence report Iranian APT Operations: Notable Campaigns and TTPs (April 2026), supplemented with public reporting.

The three sections that follow set out, in turn, what has already happened to U.S. enterprises, why the threat profile is structurally escalating, and why the common objection "we don't operate in the Middle East" no longer functions as a threat-model exemption.

» Start with KELA and stay ahead in identifying advanced threat actors and operations



What Just Happened to U.S. Enterprises?

The instinct for many U.S. enterprises is to treat Iranian APT activity as a Middle East problem.

Reporting from the past eighteen months argues against that view.

Across the same period, public reporting and KELA's own published content and webinars have surfaced named U.S.-relevant intrusions from each of the four groups examined in this series, in some cases inside the current operating quarter. The targets span banking, aviation, multinational technology, and the academic and policy-research community whose members increasingly carry enterprise identities as advisors, board members, and on-retainer experts.

The groups' portfolios, tooling, and intelligence priorities differ; what they share is that U.S. organizations no longer sit outside the target set.

Let’s meet the groups representing the largest risk to U.S. organizations.

Understanding Iran's Most Active Cyber Threat Actors

Who is MuddyWater?

The Dindoor backdoor, first observed in early February 2026 and intensifying through March, was reported by The Hacker News to target U.S. banking and finance entities, a major U.S. airport, and the Israeli operations of a U.S.-based software company.

The campaign sits inside a broader pattern in which MuddyWater consistently targets U.S. organizations in banking, critical infrastructure, and multinational technology, particularly those with operations or strategic ties to the region.

Dindoor itself is built on Deno, a runtime for JavaScript and TypeScript. That implementation choice is itself diagnostic: it enables complex post-compromise logic in an execution environment that most enterprise security controls were not built to inspect.

Who is APT42?

A campaign that researchers at Proofpoint track as UNK_SmudgedSerpent, assessed as overlapping with or linked to APT42, used carefully spoofed emails impersonating prominent U.S. foreign-policy experts (including names like Suzanne Maloney and Patrick Clawson) to target U.S.-based academics and think-tank personnel researching Iranian societal reform and IRGC militarization.

APT42's targeting does not stop at institutions: available reporting describes the group widening its attack surface by including the family members of primary targets. Cloud-resident persistence via OAuth consent and mailbox forwarding rules is documented across multiple campaigns, which means a foothold can survive without malware on a corporate endpoint.

Who is Prince of Persia (Infy)?

Analysis of the group's command-and-control infrastructure by SafeBreach Labs revealed at least 46 distinct victims across more than 20 countries. The United States at 22 victims  is the single largest national concentration outside Iran itself, ahead of Russia (21) and Germany (18).

For an actor historically filed under "Iranian diaspora surveillance", that distribution is the data point that should prompt re-evaluation.

Who is APT34 (OilRig)?

APT34's named U.S. victims are less recent; the group's intrusion against U.S. government contractor Westat in 2020, following the Soleimani assassination, is the most-cited example but its tradecraft exposes the broadest victim set of the four.

Public reporting from Trend Micro and others describes APT34 deploying backdoors directly on Microsoft Exchange servers (PowerExchange, Veaty, STEALHOOK), abusing the Exchange Web Services (EWS) API to receive commands and exfiltrate stolen data as email attachments. The traffic blends with legitimate corporate email. The group also leverages IT providers and telecommunications companies for supply-chain access into downstream government and enterprise targets.

Why the Threat Profile is Escalating

Three structural shifts in the Iranian cyber ecosystem make the current period materially different from the 2017–2022 era in which many enterprise threat models were last seriously updated.

1. Cyber-Kinetic Convergence.

The single most significant, and most carefully reported, development is the apparent integration of Iranian cyber operations with kinetic military activity. The June 2025 Jerusalem CCTV incident is the illustrative case.

According to security researchers, MuddyWater-linked infrastructure correlated with access to a compromised CCTV server in Jerusalem in the days preceding Iranian missile strikes on the city. Reporting indicates that the actor gained access to live CCTV streams, providing real-time visual intelligence of potential targets, and that this access coincided temporally with missile strikes in mid-June 2025.

This activity has not been officially confirmed by Israeli authorities, and the linkage is best characterized as a reported correlation rather than a verified attribution.  But the trajectory points to Iranian APTs operating at military tempo, providing intelligence support to operational planning, and it’s not isolated. 

Prince of Persia's operational tempo shows similar coupling: a four-month exfiltration dormancy aligning with the 12-Day War in June 2025, and a complete C2 shutdown synchronized to within days of Iran's January 2026 country-wide internet blackout, with new C2 domains registered two days before that blackout ended. Those patterns are highly consistent with state direction.

2. AI-Assisted Development and Operational Scaling.

Researchers analyzing MuddyWater's Operation Olalampo (first observed January 2026) identified stylistic artifacts in the malware binaries, including emoji-based status reporting using ✅ and ❌ markers, consistent with LLM-generated code conventions.

Google Cloud Threat Intelligence has separately reported MuddyWater's use of Gemini to conduct research supporting custom malware development. This evidence is suggestive rather than dispositive, but it points to a tradecraft inflection. The cost and time required to produce new tooling falls. Operational tempo rises. Detections built on yesterday's signatures decay faster. The same dynamic, observed against other state-aligned actors, has been associated with sharply compressed campaign-to-campaign iteration cycles.

3. Global Victim Broadening

The historical reading of Iranian APT activity as Middle East-focused is becoming outdated. MuddyWater is documented in campaigns across Egypt, Sudan, and Tanzania (telecommunications); Turkey, Pakistan, India, and the Netherlands. APT42 activity is named explicitly in the United States, United Kingdom, and Germany. Prince of Persia's footprint spans more than 20 countries.

APT34's operations are described in available reporting as expanding globally, targeting entities in Europe, the United States, and Asia. The pattern is consistent: regional priorities still drive targeting, but the operational reach has globalized.

Why “We Don’t Have Middle East Operations” No Longer Rules You Out

The most common objection from US enterprises that don't operate in the Middle East is that they are not the audience for Iranian threat reporting. Four exposure paths argue against that view, each documented across the four groups covered in this series.

Path 1: Supply Chain and IT Providers

APT34 explicitly leverages IT providers and telecommunications companies as supply-chain access points (mapped to MITRE ATT&CK T1195), using their trusted access to reach downstream government and enterprise targets. MuddyWater's Operation IconCat targeted Managed Service Providers (MSPs) and defense-adjacent software companies in Israel, with subsequent pivots through that MSP access. Enterprises without direct regional exposure can still inherit risk through vendors that do.

Path 2: Individual Targeting at the Workforce Edge

APT42's victimology centers on individuals: foreign policymakers, senior defense and government officials, journalists covering the Middle East, researchers, Iranian dissidents abroad and, in some campaigns, their family members.

U.S. enterprises that employ public commentators on Iran-relevant policy, academics on sabbatical from think tanks, journalists on retainer, or board members with regional advisory roles are surfacing attackable identities into corporate environments. APT42's preferred access pattern relies on cloud-native persistence (OAuth consent abuse, mailbox forwarding rule manipulation, persistent cloud API keys) that does not require malware on the corporate endpoint to survive.

Path 3: Exchange and Identity Infrastructure

APT34's continued use of Microsoft Exchange servers as both initial access (T1190) and command-and-control combined with malicious password filter DLLs registered on domain controllers exposes any enterprise still operating on-premises or hybrid Exchange, regardless of geography.

The group's shift toward "living off the land" and identity weaponization (stolen credentials, native administrative tools, web shells, and valid accounts under T1078) means endpoint detection alone is unlikely to surface intrusions. KELA's assessment, consistent with vendor reporting, is that this is the single highest-likelihood path for Iranian APT activity to bypass current US enterprise defenses.

Path 4: Sector Adjacency Without Geographic Adjacency

Banking and finance, critical infrastructure (notably airports and aviation), telecommunications, and multinational technology have all been named in MuddyWater 2026 targeting against U.S. entities specifically. APT34's targeting of Westat in 2020, in the wake of the Soleimani assassination, established the precedent for retaliation-coupled targeting of U.S. firms during periods of escalation.

The current period of sustained conflict in Gaza, the 12-Day War of June 2025, Operation Epic Fury in early 2026, and Iran's January 2026 internet blackout following a coordinated U.S./Israeli strike qualifies as such a period under any reasonable definition.

The Iranian Apt Series Ahead

Each of the four group-specific posts that follow uses the same executive-summary template: who they are, who they target, recent named activity, business impact, and why a Global 1000 should care. Each then walks through the group's tradecraft with named artifacts, IOCs, and MITRE technique IDs woven in.

Take note: Full ATT&CK mappings and runnable hunt queries (Sigma, KQL, and YARA where relevant) are linked out to a companion GitHub repository so the body of each post stays readable for executives skimming and analysts reading at the same time.

MuddyWater: From Regional Espionage to Military Tempo

The 2026 Dindoor campaigns against U.S. banking and a major U.S. airport. Operation Olalampo and its AI-assisted malware. Operation IconCat's hybrid espionage-destruction model. The Jerusalem CCTV correlation. RUSTRIC, PYTRIC, CHAR, GhostFetch, and the Fakeset/Castle Loader persistence chain. Why a MOIS-subordinated group not historically known for technical sophistication now poses a hybrid-operations risk. 

APT42: The IRGC's Long-Game Espionage Apparatus.

SpearSpecter and the weeks-long social-engineering build-up via WhatsApp. UNK_SmudgedSerpent's impersonation of named U.S. foreign-policy experts. The Mega Model Agency fake-website lure targeting Iranian dissidents in Hamburg. TAMECAT's fileless multi-channel C2 across Telegram, Discord, and Cloudflare Workers. Why this group reshapes the threat model for any enterprise employing people who write or speak publicly on Iran. 

Prince of Persia (Infy): Nineteen Years of Espionage, Now Globalised.

A decade-plus campaign that synchronises to Iran's domestic internet posture. Foudre, Tonnerre, and Tornado v51's Bitcoin-blockchain DGA. Telegram-native C2 abuse. The "strike-back" deployment of ZZ Stealer / StormKitty against the researchers tracking them. Why 22 named US victims is the data point that should retire the diaspora-only reading. 

APT34 (OilRig): Living Off the Land, Living Inside Your Exchange Server.

Email-based C2 via the EWS API (PowerExchange, Veaty, STEALHOOK). The Earth Simnavaz exploitation chain abusing CVE-2024-30088. Password filter DLLs on domain controllers (psgfilter.dll). Why the move from custom compiled malware to identity weaponization makes APT34 the highest-likelihood Iranian group to bypass current enterprise detection. 

Recommendations: What to Do Before the Next Post

Three near-term actions are worth the executive's reading time, regardless of where you sit in the threat-modelling cycle:

  1. Re-baseline the Iran assumption: If your most recent threat assessment frames Iran as a regional espionage problem, refresh it against the 2025–2026 reporting. The cyber-kinetic convergence evidence and the operational-tempo shift are the key deltas.
  2. Inventory your Exchange and identity exposure: Whether or not you assess direct Iranian targeting as likely, the observed tradecraft favors these surfaces. EWS API usage patterns, password filter DLL integrity, mailbox forwarding rule inventories, and OAuth application consent reviews are universally protective controls that are cheap to deploy and expensive to retrofit during an incident.
  3. Map your indirect exposure: Identify the third parties, individual contributors, and operational footprints that put you within one degree of Iranian state interest. The objection "we don't operate there" deserves to be tested rather than assumed. The four exposure paths above are the questions to start with.

Discover & Defend Against Sophisticated Adversaries

Discover how KELA helps organizations uncover, prioritize, and mitigate advanced threats with actionable cyber threat intelligence

Contact Us

Coming Next

The next post:  MuddyWater: From Regional Espionage to Military Tempo.  It opens with the Dindoor campaign against US banking and walks through MuddyWater's 2025–2026 tooling, infrastructure, and victim picture end to end.

» For tailored solution introduction and briefings on the Iranian threat picture in your sector or geography, contact our team of experts at sales@ke-la.com or for KELA customers reach out to your Customer Success Representative