State-Backed Hackers Exploit Iran War as Phishing Campaigns Target Middle Eastern Governments

Several Iranian hacktivist groups and online personas have claimed responsibility for different disruptive cyber operations. At the same time, Iranian espionage-focused threat groups are still somewhat active, even though the Iranian government shut down internet access shortly after the initial attacks by the United States and Israel.

For example, on 8 March, Proofpoint observed the Iran-aligned threat actor TA453 (also known as Charming Kitten, Mint Sandstorm, and APT42) attempting a credential-phishing attack against a US think tank. The email conversation that eventually led to the phishing attempt actually started before the conflict began, which suggests that TA453 is continuing its usual intelligence-gathering operations against its typical targets.

Although it is still unclear how broader Iranian cyber operations will develop, Proofpoint Threat Research has noticed an increase in campaigns by other state-sponsored threat actors targeting Middle Eastern government organizations since the war began. These campaigns involved both known groups and previously unidentified actors, with suspected links to China, Belarus, Pakistan, and Hamas.

Most of these campaigns used the ongoing conflict as a lure to make phishing emails appear more credible. In many cases, attackers also used compromised government email accounts to send these messages. Proofpoint believes this activity reflects two main patterns:

  1. Some threat actors are opportunistically using the war as bait while carrying out routine operations.
  2. Others are actively increasing intelligence collection efforts against Middle Eastern governments and diplomatic organizations.

Campaign #1: UNK_InnerAmbush

In early March 2026, a suspected China-aligned threat actor called UNK_InnerAmbush launched a phishing campaign targeting Middle Eastern government and diplomatic organizations.

The phishing emails were sent from a likely compromised email account:

uzbembish@elcat[.]kg

The emails contained a Google Drive link. The first wave began on March 1, just one day after the conflict started.

The phishing themes included:

  • Claims about Ayatollah Khamenei’s death
  • Messages promising sensitive images from the US “Department of Foreign Affairs”

Later waves used another theme:

  • Claims that Israel was preparing to attack Gulf oil and gas infrastructure to frame Iran

The Google Drive link hosted a password-protected ZIP or RAR archive, such as:

  • Photos from the scene.rar
  • Strike at Gulf oil and gas facilities.zip

Inside the archive were Microsoft Shortcut (LNK) files disguised as JPG images. When opened, these files ran a loader executable hidden in a subfolder.

The process worked like this:

  1. A decoy image is displayed to the user.
  2. The loader runs a legitimate signed program vulnerable to DLL sideloading:
    nvdaHelperRemoteLoader.exe
  3. This program loads a malicious DLL:
    nvdaHelperRemote.dll
  4. The DLL decrypts a Cobalt Strike payload stored in:
    WinHlp.hlp
  5. The payload is loaded into memory and connects to a command-and-control (C2) server.

C2 domain used:

support.almersalstore[.]com

The phishing emails also included tracking pixels to monitor whether targets opened the email:

hxxps://deepdive.hypernas[.]com/hypernas/api/page.php?uid=<target-email-address>


Campaign #2: TA402

In early March 2026, the threat actor TA402 (also known as Frankenstein or Cruel Jackal) launched a credential-phishing campaign against a Middle Eastern government entity.

The attackers used:

  • A compromised Iraqi Ministry of Foreign Affairs account
    [email protected][.]iq
  • An attacker-controlled Gmail account
    nqandeel04@gmail[.]com

The email subjects referenced the conflict, including:

  • A potential US ground operation in Iran
  • A Gulf military alliance against Iran

The phishing emails contained a URL that behaved differently depending on the target’s IP location:

  • Some users received a decoy PDF
  • Intended targets were shown a credential-harvesting page

The phishing page was designed to imitate Microsoft Outlook Web Application (OWA):

hxxps://mail[.]iwsmailserver[.]com/owa/auth/logon.aspx?uid=<target_specific_uuid>

If the victim entered their credentials, the data was sent via HTTP POST to an authentication endpoint on the same server.


Campaign #3: UNK_RobotDreams

On 5 March 2026, a suspected Pakistan-aligned threat actor named UNK_RobotDreams sent spear-phishing emails to India-based offices of Middle Eastern government organizations.

The email came from a fake Outlook address impersonating India’s Ministry of External Affairs:

jscop.mea.gov.in@outlook[.]com

Subject line:

“Gulf Security Alert: Iran Retaliation Impacts”

The email included a PDF attachment that showed a blurred image and a fake Adobe Reader button.

When the button was clicked, victims were redirected to:

hxxps://defenceprodindia[.]site/server.php?file=Reader_en_install

The website used geofencing:

  • Non-target users received a decoy PDF
  • Targeted victims downloaded an executable file

Downloaded file:

Reader_en_install.exe

This file acted as a .NET loader that used PowerShell through conhost.exe to download a Rust-based backdoor from:

endpoint1-b0ecetbuabcdg9cp[.]z01[.]azurefd[.]net

The malware was saved as:

VLCMediaPlayer.exe

The Rust backdoor then:

  • Collected host fingerprinting data
  • Communicated with command-and-control infrastructure hosted on Azure Front Door

This campaign overlaps with previous findings reported by Bitdefender, although Proofpoint has not linked it to a known threat actor yet.


Campaign #4: UNK_NightOwl

On 2 March 2026, another suspected state-aligned threat actor, labeled UNK_NightOwl, sent phishing emails to a government ministry in the Middle East.

Emails were sent from:

Compromised Syrian government account:
[email protected][.]sy

Fake freemail account:
war.analyse.ltd@outlook[.]com

The fake account claimed to represent a fictional organization called War Analyse Ltd.

Subject line:

“About Escalating Situation.”

The emails included a domain impersonating Microsoft OneDrive, but it actually directed victims to a fake Outlook Web App login page:

hxxps://iran.dashboard.1drvms[.]store/errors/sessionerrors/expire?client=<redacted>

This page showed a fake session error and asked users to log in again.

If victims entered their credentials, they were redirected to the legitimate website:

hxxps://iran.liveuamap[.]com/

This redirection was likely used to avoid suspicion.

Proofpoint classified this activity as a new cluster named UNK_NightOwl, since it does not match any previously known actor.


Campaign #5: TA473

Between 3–5 March 2026, the Belarus-aligned threat actor TA473 (also called Winter Vivern) targeted government organizations in Europe and the Middle East.

The phishing emails appeared to come from a spokesperson for the President of the European Council and included an HTML attachment:

european union statement on the situation in iran and the middle east.html

Notably, Proofpoint had not previously seen TA473 targeting Middle Eastern governments.

When opened, the HTML file:

  • Displayed a decoy image
  • Sent an HTTP request to:

hxxps://unityprogressall[.]org/imagecontent/getimgcontent.php?id=<target-email-address>

Proofpoint was unable to retrieve further malware during analysis. The HTTP request was likely used only to track whether the email was opened.


Campaign #6: TA453

Since the conflict began, Proofpoint has observed only one campaign from a known Iranian threat actor.

In late February to early March, TA453 (Charming Kitten / Mint Sandstorm / APT42) used the email:

McManus.Michael@hotmail[.]com

The attacker impersonated Michael McManus, head of research at the Henry Jackson Society, to target a US think tank employee.

The email exchange started before the war, when the attacker sent a benign invitation to the target’s personal email account.

After the conflict began, the conversation continued with the target’s corporate email account, showing that TA453 continued its espionage operations during the conflict.

The email invited the target to participate in a roundtable discussion on Middle East air defense.

To appear legitimate, the attacker shared a benign OneDrive link containing a PDF proposal:

Air Defense Depletion & Deterrence in the Middle East.pdf

hxxps://1drv[.]ms/b/c/cbec61ab8028f986/IQDa9igU3D3BRqiyNtth76AzAbOM6jUpa8apnuRl-zKXKow?e=E8bIfd

After building trust with the victim, the attacker later sent another message containing a malicious link disguised as a second PDF:

Air Defense Depletion & Deterrence in the Middle East – Event Overview.pdf

The link used an attacker-controlled domain: transfergocompany[.]com

It redirected victims to a fake OneDrive login page hosted on Netlify fileportalshare.netlify[.]app

The page was pre-filled with the target’s email address to increase credibility and capture login credentials.


Why This Matters

As the conflict involving Iran and regional actors continues, cyber activity related to the war shows a mix of:

  • Traditional espionage operations
  • Disruptive cyber campaigns supporting military efforts

Proofpoint also observed multiple non-Iranian threat groups targeting Middle Eastern governments using conflict-related themes.

Some actors are simply using the war as a social-engineering lure, while others appear to be increasing intelligence collection against government and diplomatic targets in the region.

This indicates that the conflict is influencing cyber operations in two ways:

  1. It provides convincing themes for phishing and social engineering.
  2. It drives intelligence collection priorities for several state-aligned threat actors seeking insights into the conflict’s regional and geopolitical impact.