Skip to content

Amazon sounds alarm as nation

Industrialcyber.Co • November 27, 2025

Recent investigations by Amazon’s threat intelligence teams have uncovered a trend they describe as cyber-enabled kinetic targeting , in which nation-state actors are systematically using cyber operations to support and sharpen physical operations. Traditional cybersecurity frameworks often treat digital and physical threats as separate domains, but Amazon’s research shows that this divide is becoming artificial. Several nation-state groups are now advancing an operational model where cyber reconnaissance feeds directly into kinetic targeting.

“We’re seeing a fundamental shift in how nation-state actors approach warfare,” C.J. Moses, CISO of Amazon Integrated Security, wrote in a recent AWS Blogs post . “These aren’t just cyber attacks that happen to cause physical damage; they are coordinated campaigns where digital operations are specifically designed to support physical military objectives.”

The research team argues that existing terminology doesn’t adequately capture the nature of these hybrid operations. The term cyber-kinetic operations usually refers to cyber attacks that directly cause physical damage, which doesn’t fit the patterns emerging here. Hybrid warfare is so broad that it loses the specificity needed to describe the tight integration of cyber activity with physical targeting. Amazon’s researchers propose cyber-enabled kinetic targeting as a more accurate description for campaigns in which cyber operations are deliberately built to support and strengthen kinetic military action.

Recent investigations by Amazon’s threat intelligence teams have uncovered a trend they describe as cyber-enabled kinetic targeting, in which nation-state actors are systematically using cyber operations to support and sharpen physical operations. Traditional cybersecurity frameworks often treat digital and physical threats as separate domains, but Amazon’s research shows that this divide is becoming artificial. Several nation-state groups are now advancing an operational model where cyber reconnaissance feeds directly into kinetic targeting.

Amazon research shows the depth of the technical infrastructure behind these operations. The threat actors rely on traffic routed through anonymizing VPN networks to mask their origins and complicate attribution. They use actor-controlled servers to maintain persistent access and command-and-control capabilities throughout their campaigns. Their ultimate targets are compromised enterprise systems, including servers that support CCTV networks, maritime platforms, and other environments rich in operational intelligence. Once inside, they stream live data from cameras and sensors, giving them actionable information that can influence targeting decisions in near real time.

Moses cited two case studies. The first case study focuses on Imperial Kitten , a threat group believed to be operating on behalf of Iran’s Islamic Revolutionary Guard Corps. The timeline shows a clear progression from digital reconnaissance to a physical strike. On December 4, 2021, Imperial Kitten compromised a maritime vessel’s Automatic Identification System platform, gaining access to critical shipping infrastructure. Amazon’s threat intelligence team detected the intrusion and worked with the affected organization to contain the incident.

On January 27, 2024, Imperial Kitten shifted from broad reconnaissance to targeted intelligence gathering by conducting specific searches for AIS location data tied to a particular vessel. Days later, on February 1, 2024, US Central Command reported a missile strike by Houthi forces on that same vessel. The attack failed, but the alignment between the threat actor’s cyber reconnaissance and the subsequent kinetic strike is striking. The case illustrates how cyber activity can equip adversaries with the precise intelligence required to support targeted physical attacks on maritime infrastructure, which remains central to global commerce and military logistics.

The second case study examines MuddyWater , a threat group the U.S. government links to Rana Intelligence Computer Company, which operates under Iran’s Ministry of Intelligence and Security. This case shows an even more direct connection between cyber activity and kinetic action. In May this year, MuddyWater set up a server devoted to cyber network operations, creating the infrastructure for its campaign.

For the cybersecurity community, this research serves as both a warning and a call to action. Defenders must adapt their strategies to address threats that span both digital and physical domains. Organizations that historically believed they weren’t of interest to threat actors could now be targeted for tactical intelligence. We must expand our threat models, enhance our intelligence sharing, and develop new defensive strategies that account for the reality of cyber-enabled kinetic targeting across diverse adversaries.

These findings call for broader threat modeling that accounts for more than the immediate impact of a cyber incident. Organizations need to understand how a compromised system could be exploited to support physical attacks against their own operations or third parties.

Critical infrastructure operators, from maritime platforms to urban surveillance networks, must recognize that their systems hold value not only for espionage but also as tools that can guide kinetic action. The cases also underscore the importance of intelligence sharing across private industry, government, and international partners. When cyber activity directly enables physical attacks, attribution and response become more complicated, demanding closer coordination across cybersecurity, military, and diplomatic channels.

“We believe that cyber-enabled kinetic targeting will become increasingly common across multiple adversaries,” according to Moses. “Nation-state actors are recognizing the force multiplier effect of combining digital reconnaissance with physical attacks. This trend represents a fundamental evolution in warfare, where the traditional boundaries between cyber and kinetic operations are dissolving.”

Extracted Entities

Countries (1)