IRON VEIL
56M RECORDS
IRAN IRGC
SCADA/ICS
Threat IntelligenceTLP:AMBERIranSpecial ReportMarch 28, 2026

Operation IRON VEIL

Special Intelligence Report — Cyber Dimensions of the Iran Conflict. 56,362,322 darknet intelligence records. Seven threat actors. Six operational theaters.

Scroll

This special intelligence report presents findings from the MTAC Intelligence platform Operation IRON VEIL investigation — a 91-day deep-packet attribution campaign analyzing 56,362,322 darknet intelligence records across seven Iranian-nexus threat actors operating in six distinct operational theaters. The report provides actionable intelligence for critical infrastructure operators, government agencies, and private sector organizations with exposure to Iranian cyber operations.

Executive Summary

The MTAC investigation reveals a coordinated multi-theater Iranian cyber campaign of unprecedented scale. Key metrics from the 91-day collection window:

5.69M
Iran Sessions
215K
Gulf Targeted
400K
SCADA / ICS
575K
Israel Theater
45.2M
US Targeted
4.2M
Canada CI
1,795
Deep Packet Attr
91
Active Days

Key Findings

Critical Intelligence Findings

1. US infrastructure accounts for 80.2% of all targeted sessions (45.2M records), with energy and financial services as primary verticals. Targeting intensity increased 340% following Operation Epic Fury.

2. SCADA/ICS exposure across North American critical infrastructure exceeds 400,000 identified sessions, with confirmed pre-positioning activity against water treatment and power distribution networks.

3. Seven distinct Iranian-nexus threat actors are operating with reduced central coordination, creating unpredictable and overlapping campaign patterns that complicate traditional attribution models.

4. Gulf States theater shows 215,000 targeted sessions concentrated on UAE, Saudi Arabia, and Bahrain financial infrastructure, consistent with economic destabilization objectives.

5. Canada critical infrastructure targeting (4.2M sessions) represents a significant escalation, with energy pipelines and telecommunications providers as primary targets.

6. Deep packet attribution identified 1,795 unique indicators linking campaign infrastructure to IRGC Cyber Command and MOIS technical units, with high-confidence nexus assessments.

Threat Actor Profiles

Seven Iranian-nexus threat actors were identified operating within the IRON VEIL collection window. The following attribution table summarizes nexus assessments and threat scores.

Threat ActorNexusThreat ScoreConfidence
APT33 (Elfin / Peach Sandstorm)IRGC9.0 / 10High
APT34 (OilRig / Helix Kitten)MOIS8.0 / 10High
MuddyWater (Mercury)MOIS8.0 / 10High
CyberAv3ngersIRGC-CEC9.0 / 10High
Cotton Sandstorm (Emennet Pasargad)IRGC7.0 / 10High
Agrius (Pink Sandstorm)MOIS8.0 / 10High
Tortoiseshell (Imperial Kitten)IRGC7.0 / 10High

Full Report Contents

The complete Operation IRON VEIL report contains the following sections. Download the full PDF to access all findings, attribution data, and actionable recommendations.

01Iran-Nexus Traffic Analysis
02Gulf States Theater
03SCADA/ICS Exposure
04US Escalation Indicators
05Canada CI Targeting
06Deep Packet Attribution
07MITRE ATT&CK Mapping
08Predictive Assessment
0924 Actionable Recommendations
Gated Content Complete your details below to download the full report

Download the Full Report

Access the complete Operation IRON VEIL intelligence report including deep-packet attribution data, full MITRE ATT&CK mappings, SCADA/ICS exposure analysis, theater-by-theater breakdowns, predictive threat assessments, and 24 actionable defensive recommendations.

By submitting this form, you will receive the report and periodic threat intelligence updates from Mjolnir Security. You can unsubscribe at any time by clicking the link in any email. We will never share your information with third parties. Privacy Policy
Need Immediate Assistance?

For emergency incident response or to activate Mjolnir Security's High-Intensity Threat Hunting (HITH) protocol, contact the Global Tracking Center at +1 833 403 5875 or visit mjolnirsecurity.com.

Produced by: MTAC Intelligence platform  |  Published: March 28, 2026  |  Classification: TLP:AMBER