Executive Summary
Iranian government-linked actors expanded targeting from water utilities into U.S. telecommunications and energy sectors in September 2026, according to NBC News reporting citing four sources with direct access to government and industry threat information [1]. Separately, Group-IB attributed a Telegram-based espionage backdoor (HEAVYGRAM) and a Delphi-based utility (CRUDEEXCLUDE) to the Handala persona, providing the first vendor-validated technical tooling tied to this actor's post-ceasefire operations [7]. These developments, occurring five months after the April 2026 ceasefire, confirm that the operational pause in kinetic conflict redirected rather than reduced Iranian cyber activity against Western targets[8].
What Changed Since August 2026
- Iran attempted cyberattacks on range of U.S. infrastructure, sources say
- Iran's Hackers Target 3 US Sectors, CISA Warns [2026]
- Iran's cyber attack strategy is 'perfect weapon' against US
- Handala hacker group publishes selfie images of 700 Israeli 'security' personnel
- Handala hacker group publishes selfie images of 700 Israeli security
- Handala published about 700 selfies of Israeli security forces employees
- Handala reveals new cyber campaign against Israel-linked security figures
- Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
- Despite Cease-Fire, Iran's Hackers Haven't Logged Off
- Shaky ceasefire unlikely to stop cyberattacks from Iran-linked hackers for long
- Stryker cyberattack contained, but experts warn repair costs could soar
- Stryker attack wiped tens of thousands of devices, no malware needed
- The Stryker Hack: How One Compromised Admin Account Led to 200,000 Wiped Devices
- Stryker Cyberattack: Handala Iran Hack Wiped 200K Devices
- The Stryker Story: When Device Management Platform Becomes a Weapon
- Stryker Cyberattack: MDM Compromise & Device Security
- Stryker Wiper Attack: What Security Teams Need to Know Now
Iranian Targeting Expands from Water Utilities to Telecom and Energy
- What happened: NBC News reported on September 2 that Iranian government-linked hackers attempted breaches of U.S. telecommunications networks and energy providers "in recent weeks," moving beyond the water utility targeting documented since 2023 [1]. Shattered.io corroborated this expansion and noted associated CISA warnings [2]. The National framed the activity as a post-conflict escalation following U.S. and Israeli strikes on Iran earlier in 2026 [3].
- Cyber implications: This lateral expansion across critical infrastructure sectors indicates that defenders in telecom and energy now face the same threat that water utilities have contended with since the CyberAv3ngers campaigns of 2023-2024 [1]. The CISA joint advisory AA26-097A, updated through July 2026, documents TTPs and IOCs for Iranian exploitation of internet-facing PLCs that likely form the technical foundation for this broader campaign.
- Sectors at risk: Telecommunications, energy/electric utilities, water/wastewater systems, OT/ICS environments
- Confidence: Moderate (Tier 1 government advisory baseline, Tier 3 multi-source reporting [1][3], secondary corroboration [2])
- Sources: [1], [2], [3],
HEAVYGRAM Backdoor and CRUDEEXCLUDE Attributed to Handala
- What happened: Group-IB attributed a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility called CRUDEEXCLUDE to the Handala persona [7]. HEAVYGRAM supports remote command execution, system/network/process discovery, Telegram session file exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence through Windows autorun registry keys [7]. This represents a shift from Handala's earlier destructive operations (the March 2026 Stryker MDM wipe [9][10]) toward sustained espionage capability.
- Cyber implications: The HEAVYGRAM tooling targets Windows endpoints with Telegram installed, making it relevant to organizations where Telegram is used for operational communications. The DLL sideloading and autorun persistence mechanisms are detectable with standard EDR telemetry and registry monitoring. Defenders should treat Group-IB's published IOCs as actionable for hunt operations.
- Sectors at risk: Government/defense personnel, journalists, dissidents, any enterprise permitting Telegram on managed endpoints
- Confidence: Low (single vendor attribution from Group-IB via Tier 3 reporting [7]; no corroborating vendor analysis identified)
- Sources: [7]
Handala Claims Mobile Surveillance via 'Na'em' Tool
- What happened: Handala claimed to have covertly captured approximately 700 selfie images from mobile phones of Israeli security personnel using a tool called "Na'em" [4]. The claim was reported by Press TV [4], ABNA24, and Pravda EN [5][6]. No independent verification of the claim's scale or the tool's capabilities has appeared outside of these Iranian state-adjacent and pro-Iran outlets.
- Cyber implications: If the Na'em tool is functional, it represents a mobile surveillance capability that could target personnel across allied nations, not just Israel. However, the claim's sourcing (exclusively Tier 4, pro-Iran media) and the absence of any technical analysis or IOCs mean defenders should track the claim without treating it as confirmed. The pattern mirrors Handala's history of inflating operational impact (see Stryker discrepancy below).
- Sectors at risk: Government/defense personnel, mobile device ecosystems
- Confidence: Moderate (all sourcing is Tier 4 with no independent technical validation [4][5][6])
- Sources: [4],, [5], [6]
Stryker Impact Discrepancy Remains Unresolved, Illustrates Inflation Pattern
- What happened: The March 2026 Stryker MDM wiper attack continues to carry two incompatible impact figures. SC Media and BleepingComputer reported approximately 80,000 devices wiped and characterized it as "tens of thousands" [9][10]. Multiple vendor blogs and derivative outlets repeated Handala's self-reported figure of 200,000+ devices and 50TB exfiltrated without independent verification [11][12][13][14][15].
- Cyber implications: This unresolved 2.5x discrepancy between independently sourced and self-reported figures is directly relevant to how CTI teams should weight Handala's September claims (the Na'em "700 selfies" claim and any future impact reporting). The Stryker incident confirmed that Handala possesses real destructive capability. The inflation pattern means defenders should calibrate impact assessments against independently verified data, not actor claims.
- Sectors at risk: Healthcare/medical device manufacturing, enterprise MDM/device management
- Confidence: Moderate (factual discrepancy documented across multiple sources [9][10][11][12])
- Sources: [9], [10], [11], [12], [13], [14], [15]
Ceasefire Failed to Reduce Iranian Cyber Operational Tempo
- What happened: The April 2026 ceasefire between Iran and the U.S./Israel was followed within days by analyst assessments that cyber operations would continue[8]. The New York Times reported Iran was "positioning itself to mount a bigger retaliation if peace talks do not resume". The LA Times quoted Handala directly pledging continued attacks on both Israeli and U.S. targets [8]. September's sector-expansion reporting [1] and new tooling [7] validate these early predictions.
- Cyber implications: The ceasefire created a permissive environment for cyber operations: reduced international scrutiny compared to active kinetic conflict, but retained the strategic motivation. CTI teams should model Iranian cyber activity as independent of the kinetic conflict's status. Operational tempo is almost certainly driven by strategic positioning objectives rather than tactical retaliation timelines.
- Sectors at risk: U.S. critical infrastructure broadly
- Confidence: Moderate (multiple Tier 3 analytical sources confirmed by September operational evidence [1][8])
- Sources: [1],, [8]
Strategic Context
- National strategy: Iran's cyber operations serve as an asymmetric response mechanism to compensate for conventional military inferiority relative to the U.S. and Israel. The April 2026 ceasefire did not alter the strategic calculus; reporting from April indicated Iran views cyber operations as a tool for maintaining coercive pressure while preserving diplomatic flexibility. The September expansion into telecom and energy sectors [1] is consistent with a strategy of broadening the target surface to increase perceived cost to adversaries without crossing kinetic thresholds.
- Key actors and mandates: The IRGC Cyber-Electronic Command (IRGC-CEC) and the Ministry of Intelligence and Security (MOIS) are the two primary organizational drivers of Iranian cyber operations. CyberAv3ngers, linked to IRGC, conducted the 2023-2024 water utility campaigns and are assessed as likely connected to the expanded infrastructure targeting documented by CISA and NBC [1]. Handala operates as a persona that bridges hacktivist branding with state-aligned operational objectives, now attributed with both destructive (Stryker wiper [9][10]) and espionage (HEAVYGRAM [7]) capabilities.
- Ongoing strategic objectives: Iran's cyber program serves three concurrent objectives: (1) pre-positioning access in adversary critical infrastructure for potential future destructive use, as evidenced by the PLC exploitation campaign; (2) intelligence collection against Israeli security and defense targets, demonstrated by the HEAVYGRAM tooling [7] and Na'em claims [4]; and (3) information operations through inflated impact claims designed to amplify deterrent perception beyond actual capability [11][12]. The September evidence supports all three lines of effort operating simultaneously.
Sources: [1],, [4], [7],, [9], [10], [11], [12]
Outlook
Three scenario branches merit monitoring through October 2026:
Escalation scenario (peace talks collapse): The New York Times assessed in April that Iran is positioning for "bigger retaliation if peace talks do not resume". If diplomatic channels stall or collapse in Q4 2026, defenders should expect acceleration of pre-positioning activity in U.S. critical infrastructure, potentially including attempts at demonstrable (not just access-based) impact in telecom or energy sectors. This would likely be preceded by increased scanning activity detectable via the IOCs in CISA advisory AA26-097A.
Steady-state scenario (status quo continues): If the ceasefire holds without meaningful diplomatic progress, the current pattern (quiet access expansion plus periodic Handala claims for information effect) will almost certainly continue. Defenders in the three targeted sectors (water, telecom, energy) should expect sustained intrusion attempts at current or slightly elevated rates [1][2]. Handala will likely continue releasing claims via state-adjacent media outlets to maintain perceived operational pressure [4].
De-escalation scenario (formal negotiations resume): Even meaningful diplomatic progress is unlikely to halt ongoing cyber operations. The April ceasefire itself produced no reduction[8]. A formal agreement might reduce destructive operations but would almost certainly not affect espionage or pre-positioning activity. Palo Alto's Unit 42 threat brief, last updated April 17 with no September refresh, represents a gap in vendor coverage that defenders should track for updates [16].
Sources: [1], [2],, [4],,, [8], [16]
Red Sheep Assessment
Assessment (Moderate confidence): The September source material, taken collectively, indicates that Iranian cyber operations have entered a phase where capability development outpaces the information operations designed to amplify it, and defenders should pay closer attention to the quiet capability signals than the loud claims.
The HEAVYGRAM/CRUDEEXCLUDE attribution by Group-IB [7] is more operationally significant than the Na'em "700 selfies" claim [4][5][6], yet the Na'em claim received broader media amplification across state-adjacent outlets. This inversion, where the less verifiable claim gets more coverage, is consistent with a deliberate information operations strategy: use Handala's public persona to draw attention and generate deterrent perception while actual espionage tooling development proceeds with less scrutiny.
An alternative interpretation merits consideration. The sector expansion reported by NBC [1] could reflect not a deliberate strategic pivot but opportunistic access: Iranian operators may be probing telecom and energy targets because those sectors have more internet-exposed OT/ICS devices than previously mapped, rather than because of a top-down directive to expand targeting. The distinction matters for defenders because opportunistic scanning across sectors requires different detection prioritization than targeted campaigns against specific organizations.
The absence of an updated Unit 42 threat brief since April [16] is itself a data point. Either the vendor community has not observed sufficient new technical evidence to warrant an update (which would undercut the significance of NBC's sourcing), or the activity is being tracked through classified channels that haven't yet surfaced publicly. Defenders should weight the CISA advisory's continued updates through July as the stronger signal of ongoing government concern.
Defender's Checklist
- ▢[ ] Review and implement all IOCs and detection signatures from CISA advisory AA26-097A (updated July 22, 2026). Specifically audit for internet-exposed PLCs and OT devices in your environment. If you're in telecom or energy sectors, apply the same controls previously recommended for water utilities.
- ▢[ ] Hunt for HEAVYGRAM indicators on Windows endpoints: monitor for new autorun registry key creation (HKCU\Software\Microsoft\Windows\CurrentVersion\Run), DLL sideloading activity in non-standard paths, and Telegram session file access (tdata directory) by processes other than Telegram.exe [7].
- ▢[ ] Audit MDM platform administrative accounts for MFA enforcement, session token expiry, and anomalous login patterns. The Stryker incident demonstrated that a single compromised MDM admin credential can enable mass device wiping without deploying malware [9][10][11].
- ▢[ ] If Telegram is permitted on enterprise-managed endpoints or mobile devices, evaluate whether it should remain authorized given its confirmed use as a C2 channel and exfiltration vector by Iranian-linked actors [7]. At minimum, log and alert on Telegram session file access by non-Telegram processes.
- ▢[ ] Establish a standing query or alert for Iranian government-linked threat reporting across CISA, NSA, and FBI joint advisory feeds. The expansion into new sectors [1] occurred incrementally; early advisory consumption provides lead time for defensive posture adjustments.
Sources
- [1] "Iran attempted cyberattacks on range of U.S. infrastructure, sources say" - NBC News, https://www.nbcnews.com/politics/national-security/iran-attempted-cyberattacks-range-us-infrastructure-sources-say-rcna595424
- [2] "Iran's Hackers Target 3 US Sectors, CISA Warns [2026]" - Shattered.io, https://shattered.io/iran-cyber-attacks-us-infrastructure-2026/
- [3] "Iran's cyber attack strategy is 'perfect weapon' against US" - The National, https://www.thenationalnews.com/future/technology/2026/09/02/iran-cyberattack-hack-us-infrastructure/
- [4] "Handala hacker group publishes selfie images of 700 Israeli 'security' personnel" - Press TV, https://www.presstv.co.uk/Detail/2026/09/19/776584/Handala-hacker-group-publishes-selfie-images-of-700-Israeli-security-personnel
- [5] "Handala published about 700 selfies of Israeli security forces employees" - Pravda EN, https://news-pravda.com/world/2026/09/19/2604103.html
- [6] "Handala reveals new cyber campaign against Israel-linked security figures" - Pravda EN, https://news-pravda.com/world/2026/09/19/2604262.html
- [7] "Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords" - The Hacker News, https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html
- [8] "Shaky ceasefire unlikely to stop cyberattacks from Iran-linked hackers for long" - Los Angeles Times, https://www.latimes.com/world-nation/story/2026-04-09/shaky-ceasefire-unlikely-to-stop-cyberattacks-from-iran-linked-hackers-for-long
- [9] "Stryker cyberattack contained, but experts warn repair costs could soar" - SC Media, https://www.scworld.com/news/stryker-cyberattack-contained-but-experts-warn-repair-costs-could-soar
- [10] "Stryker attack wiped tens of thousands of devices, no malware needed" - BleepingComputer, https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/
- [11] "The Stryker Hack: How One Compromised Admin Account Led to 200,000 Wiped Devices" - Lumos, https://www.lumos.com/blog/stryker-hack
- [12] "Stryker Cyberattack: Handala Iran Hack Wiped 200K Devices" - Tech Insider, https://tech-insider.org/stryker-cyberattack-handala-iran-mdm-wipe-2026/
- [13] "The Stryker Story: When Device Management Platform Becomes a Weapon" - Guardz, https://guardz.com/blog/the-stryker-story-when-device-management-platform-becomes-a-weapon/
- [14] "Stryker Cyberattack: MDM Compromise & Device Security" - Ordr, https://ordr.net/blog/stryker-corporation-cyberattack
- [15] "Stryker Wiper Attack: What Security Teams Need to Know Now" - 7AI, https://7ai.com/stryker-wiper-attack-what-security-teams-need-to-know-now
- [16] "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)" - Palo Alto Networks Unit 42, https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/