APTIran

Origin
IR
Primary motivation
ideology
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:26:04

Targeted industries: government-and-public-sector education-and-nonprofits financial-services healthcare-and-pharmaceutical energy-and-utilities

Targeted regions: country_code:il country_code:jo

Context

APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of government ministries, hospitals, universities, and financial institutions as retaliation for Israeli military operations. The group has leaked over 350,000 Israeli government login credentials and approximately 300 internal databases, while also threatening to create a 'zombie' network from infected devices. They have reportedly deployed ransomware strains such as ALPHV and LockBit as part of their offensive toolkit. Additionally, APTIran has made unverified claims of compromising Israeli water control systems and the state-owned food security agency Jordan Silos and Supply General Co.

Reports & references

  • sophos.com — Hacktivist Campaigns Increase As United States Iran And Israel Conflict Intensifies (report)
  • Cisco Talos — Talos Developing Situation In The Middle East (report)

External references