The cyber fallout from the conflict prompted by US and Israeli strikes on Iran is here.
Hacktivist groups and state-backed threat actors are now claiming responsibility for various cyber-attacks as the Middle East conflict seeps into the cyber sphere, according to analysis from Proofpoint.
While Proofpoint researchers admit that it is unclear how Iranian cyber operations will proceed – it only observed one targeted attack from an Iranian group since the start of the recent military campaign – researchers are seeing an increase in campaigns from other state-backed groups.
Known groups and previously unseen groups alike took advantage of the global dissary – Proofpoint researchers suspect that China, Belarus, Pakistan, and Hamas were behind some of the operations.
Groups leveraged interest in the ongoing conflict as an alluring subject to reel targets in, often using compromised accounts of government authorities for phishing email campaigns.
Analysts at Proofpoint see organisations taking advantage of the current conflict to carry out ongoing operations as well as expanding their espionage and information gathering concerning key entities in the region.
A group potentially aligned with China conducted a phishing campaign targeting governments in the Middle East by leveraging supposed information about Ayatollah Khamenei’s death, as well as further military operations by the US in Iran. Threat actors claimed to have “secret on-site images” from the US Department of Foreign Affairs.
A different group which goes by the names Frankenstein and Cruel Jackal targeting a government organisation in the Middle East using a compromised email from the Ministry of Foreign Affairs of Iraq. The phishing email referenced a potential US ground operation in Iran and other attention-grabbing lures routed in the conflict.
A threat actor group potentially aligned with Pakistan targeted India-based offices in the Middle East, impersonating India’s Ministry of External Affairs, with a subject line: Gulf Security Alert: Iran Retaliation Impacts.
Other cyber operations followed a similar pattern, with threat actors leveraging compromised government emails or impersonating authorities, luring in targets with information or updates on the evolving conflict.
Recommended reading
- Oversight Board Slams Meta for Overlooking Fake AI Posts About Iran Conflict
- NCSC Warns UK Business to Prepare for Iranian Cyber-attacks
- DDoS Attacks Surged in 2025 As Hacktivism Emerges
Finally, an Iranian-aligned threat actor, Charming Kitten, targeted an individual at a US thinktank, though the original targeting occurred prior to the war beginning. However, the campaign continued during the conflict, showing that Iran is still capable of cyber espionage.
The emails built up a rapport with the target by inviting them to speak on an air defense roundtable, only then to invite them with a malicious PDF link.
“While several of these groups incorporated the war-themed lure content in operations that are largely consistent with typical targeting remits, others demonstrated a shift toward intelligence collection against Middle Eastern government and diplomatic entities,” Proofpoint said.





