Rabat – Cybersecurity firm Halcyon says Iranian-linked hackers are increasingly borrowing tactics from ransomware gangs and using them in destructive cyber attacks, according to a threat report released this week.
The company says several recent incidents show attackers deploying malware that behaves like ransomware but ultimately destroys data rather than simply locking it for payment. In these cases, systems are encrypted and ransom notes appear, but the malware is designed to wipe files and prevent recovery.
Halcyon says the approach allows attackers to disguise politically motivated cyber operations as ordinary cybercrime.
The report places the activity in the context of rising geopolitical tensions involving Iran, noting that Iranian cyber operations have historically intensified during periods of regional escalation.
Researchers say the tactics echo earlier destructive campaigns linked to Iran, including the Shamoon malware attacks that wiped tens of thousands of computers at Saudi Aramco in 2012. Later variants of the same malware were used against organizations across the Middle East, spreading through corporate networks and erasing data.
Halcyon’s latest findings also reference attempts to target cloud infrastructure tied to Amazon Web Services data centers in the Gulf region. The company said the activity forms part of a broader pattern of cyber operations observed recently as tensions in the region increase.
Read also: Drone Strikes Hit 3 AWS Infrastructure in the UAE and Bahrain
According to the report, Iranian-linked actors often gain access to networks long before destructive activity begins. Initial entry is typically achieved through phishing emails, stolen login credentials or the exploitation of vulnerable internet-facing services.
Once inside a network, attackers move laterally across systems while mapping infrastructure and maintaining persistent access. Malware or destructive tools can then be deployed across multiple machines at once.
Security researchers frequently attribute Iranian cyber activity to several groups tracked in the industry as APT33, APT34 and APT35. These groups have previously targeted energy companies, government agencies and technology firms in the United States, Europe and the Middle East.
Halcyon says the increasing use of ransomware-style techniques by state-linked actors reflects a wider shift in the cyber threat landscape. Tools and methods developed by cybercriminal groups are now widely reused by state-backed hackers, making attacks harder to attribute and sometimes harder for victims to identify in their early stages.
The company said the campaigns it analyzed primarily targeted sectors whose disruption can have significant operational impact, including energy, transportation, healthcare, logistics, technology companies and government institutions.








