Full Report
In a message highlighted with emojis of a coffin and an American flag, the same Iran hacking group that claimed responsibility for recent breaches of U.S. water systems offered a bounty for dead or alive Americans. APT IRAN’s Saturday post on their Telegram channel began, “We are waiting.” “We will pay up to $15,000 (equivalent…
Analysis Summary
# Threat Actor: APT IRAN
## Attribution & Identity
* **Actor Identification:** APT IRAN
* **Known Associations:** Closely linked to the Islamic Revolutionary Guard Corps (IRGC)-affiliated group **CyberAv3ngers**.
* **National Affiliation:** Iran (aligned with the Iranian Ministry of Intelligence and IRGC).
## Activity Summary
* **Bounty Campaign (October 2026):** Offered financial rewards ($15,000 for live capture, $2,500 for killing) for Americans or "hired terrorists" allegedly operating within Iran.
* **Information Operations:** Used Telegram to spread claims of Mossad and U.S. infiltration and coordinated with Iranian state media (Mehr News Agency) to highlight the arrest of "sabotage networks."
* **Telecommunications Targeting:** Claimed responsibility for a multi-city AT&T outage in Texas (September 2026), though the carrier denied evidence of a breach.
* **Water Sector Attacks:** Claimed responsibility for breaching U.S. water utilities in late July 2026, describing them as a "warning" of their capabilities.
## Tactics, Techniques & Procedures
* **Psychological Operations (PSYOP):** Use of Telegram for public threats, propaganda, and bounty offers to incite violence or fear.
* **OT/ICS Targeting:** Specifically focuses on internet-connected operational technology (OT) and programmable logic controllers (PLCs).
* **Exploitation of Known Vulnerabilities:** While specific CVEs aren't in this text, CISA notes targeting of internet-exposed devices.
* **Infrastructure Manipulation:** Claims of tampering with telecommunications and utility control systems.
* **Social Coordination:** Utilizing national security hotlines (Hotline 113) to integrate cyber operations with physical domestic security.
## Targeting
* **Sectors:** Water and Wastewater Systems, Telecommunications, Critical Infrastructure, Energy (Electricity).
* **Geography:** Primarily the United States (specifically Texas and Minnesota mentioned); domestic Iranian targets (suspected infiltrators).
* **Victims:** AT&T (claimed), unnamed U.S. water utilities.
## Tools & Infrastructure
* **Malware/Tools:** Mention of Molotov cocktails and tools for destroying surveillance cameras (physical sabotage tools mentioned in Telegram posts).
* **Communication Channels:** Telegram.
* **Control Systems:** Programmable Logic Controllers (PLCs).
* **Infrastructure:** Iranian National Security Hotline 113.
## Implications
APT IRAN represents a hybrid threat where cyber operations are used to support kinetic threats and state propaganda. Their focus on U.S. critical infrastructure—specifically water and telecommunications—indicates a strategy of "deterrence through disruption," intending to demonstrate that U.S. domestic life can be impacted by Iranian cyber capabilities. The transition from digital disruption to offering bounties for physical harm suggests an escalation in aggressive rhetoric and potential real-world violence.
## Mitigations
* **OT Security:** Disconnect Programmable Logic Controllers (PLCs) and other OT equipment from the public-facing internet.
* **Access Control:** Implement strong multi-factor authentication (MFA) and change default passwords on all industrial control systems.
* **CISA Guidance:** Adhere to CISA advisory AA26-097A regarding Iranian-affiliated targeting of OT devices.
* **Network Segmentation:** Isolate critical infrastructure networks from business networks to prevent lateral movement.
* **Monitoring:** Increase vigilance for suspicious activity on Telegram and other social platforms used for actor communication and coordination.