Iran Exploits Cyber Domain to Aid Kinetic Strikes
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific
The country deploys "cyber-enabled kinetic targeting" prior to — and following — real-world missile attacks against ships and land-based targets.
Iranian advanced persistent threat (APT) groups have used cyberattacks for scoping out targets ahead of real-world attacks to improve operations and following kinetic strikes to assess damage, making Iran the latest nation to blend cyberattacks and military operations, according to cyber-conflict experts.
In a Nov. 19 analysis, Amazon used data from its vast cloud network to connect the dots between cyber events and military operations, highlighting two cases where Iran used cyberattacks to gain reconnaissance into real world targets — hacking ship systems before a missile attack and compromising CCTV cameras in Israel before and during missile attacks on Jerusalem. The threat actors used VPN networks, dedicated server infrastructure, and compromised corporate systems to construct their attack infrastructure.
Calling the strategy "a fundamental shift in how nation-state actors approach warfare," Amazon researchers termed the approach "cyber-enabled kinetic targeting."
"Traditional cybersecurity frameworks often treat digital and physical threats as separate domains, [but] research by Amazon demonstrates that this separation is increasingly artificial," the researchers stated in the analysis. "Multiple nation-state threat groups are pioneering a new operational model where cyber reconnaissance directly enables kinetic targeting."
Amazon is not the only company to warn of these attacks, and Iran is not the only country known to use them .
Most Iranian groups are likely trying to compromise devices to provide "on the ground" intelligence for Iran's military, says Sergey Shykevich, threat intelligence group manager for cybersecurity firm Check Point Software. During the 12-day war this past June, exploitation of vulnerabilities in IP cameras in Israel jumped by 15 times, he says.
"We know that most of that was connected to specific Iranian groups," Shykevich says. "We definitely saw sharp increase in targeting of cameras in Israel."
While other countries are likely using the same tactics, Amazon gained visibility into Iranian activities because of its in-depth view across its network and those of its customers. Amazon threat intelligence researchers used telemetry from honeypot systems to gain visibility into suspicious patterns, threat actors' infrastructure, and the topologies of command-and-control networks. Opt-in customer data and intelligence sharing from industry partners provided additional pieces that could be used to assemble the rest of the puzzle.
In one case, the researchers detected when Imperial Kitten, a group linked to Iran's Islamic Revolutionary Guard Corps (IRGC), compromised the Automatic Identification System (AIS) platform for different maritime vessels, starting in December 2021. In some cases, the attackers gained access to CCTV cameras aboard the vessels. The activity continued, and in January 2024, the attackers focused on a specific vessel. Five days later, Houthi forces targeted the ship with a missile strike, which "was ultimately ineffective," the Amazon researchers stated in the analysis .
"This case demonstrates how cyber operations can provide adversaries with the precise intelligence needed to conduct targeted physical attacks against maritime infrastructure — a critical component of global commerce and military logistics," the threat researchers stated.
In a second incident, the researchers tracked the attempts by MuddyWater, a group linked to Iran's Ministry of Intelligence and Security (MOIS), to use livestreams from compromised CCTV servers in Jerusalem to help targeting and damage assessment from a broad missile strike against the city.
Amazon separated these cyber-enabled kinetic targeting from other blended forms of military operations, such as hybrid warfare — a term that is too broad — and cyber-kinetic operations — which usually applies to cyberattacks that cause real-world damage, the company's researchers said.
Other countries use cyber-enabled targeting, but likely not to the extent that Iran has or will. In Russia's invasion of Ukraine , "there was no statistically significant difference in targeting before and after the invasion," according to a paper on the Russo-Ukrainian war published by the Center of International and Strategic Studies (CSIS) in July 2023.
"The utility of cyber operations rests in setting conditions and intelligence more than in direct application during large-scale combat operations," the paper stated . "While cyber-enabled targeting supports combat, the data shows that larger cyber campaigns do not radically shift during wartime."
However, Iran has increasingly found itself isolated with fewer proxies willing to take action outside of its borders, says Alexis Rapin, a cyber-threat analyst with cybersecurity firm ESET. Israel's attacks on Hezbollah in Lebanon has weakened those allies of Iran, while the country had to pull forces out of Syria. As Iran continues to reinforce its network of proxies , cyber reconnaissance and espionage allows action-at-a-distance, he says.
"Cyber could be an alternative to compensate for this loss of visibility on the ground and, for instance, the loss of human [intelligence] sources," he says. "One of the added values of cyber espionage is that ... it enables near real-time monitoring of the situation."
Seeking those and other benefits, Iran will keep experimenting with what cyber can achieve, Rapin says.
Robert Lemos, Contributing Writer
Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline Journalism (Online) in 2003 for coverage of the Blaster worm. Crunches numbers on various trends using Python and R. Recent reports include analyses of the shortage in cybersecurity workers and annual vulnerability trends.
2025 State of Threat Intelligence: What it means for your cybersecurity strategy
Gartner Innovation Insight: AI SOC Agents
State of AI and Automation in Threat Intelligence
Guide to Network Analysis Visibility Solutions
Organizations Require a New Approach to Handle Investigation and Response in the Cloud
Identity Security in the Agentic AI Era
How AI & Autonomous Patching Eliminate Exposure Risks
Securing the Hybrid Workforce: Challenges and Solutions
Cybersecurity Outlook 2026
Threat Hunting Tools & Techniques for Staying Ahead of Cyber Adversaries
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
