Iran’s cyber operations have long been a source of concern, with many assuming that only critical infrastructure is at risk. However, recent attacks demonstrate that this assumption is misguided. The groups behind these incidents, including Handala and Ababil of Minab, are not simply targeting high-profile targets; they are instead on the hunt for easily exploited vulnerabilities or insecure systems.
These cyber actors often cloak themselves in the mask of hacktivism, using terms like “cyber activism” to justify their actions. But in reality, they are largely opportunistic, exploiting weaknesses that could be used by more sophisticated threat actors with malicious intent. A recent attack on Stryker, a medical device manufacturer, saw over 200,000 hosts remotely wiped in an incident that disrupted manufacturing and impacted the company’s earnings.
The vulnerability that enabled this attack was likely exposed through credentials stolen via commodity malware and provided for sale via illicit channels. This highlights the opportunistic nature of these events, where cyber actors are essentially hunting “Shodan Safaris” – scanning for easily exploitable vulnerabilities or insecure systems to target. A law firm or logistics hub with an exposed programmable logic controller or an unpatched VPN is just as attractive a target.
Many companies don’t realize how much of their infrastructure is externally accessible, or how little it takes to exploit what’s exposed. In fact, the attack on Vyncs, a GPS tracking platform used across the logistics sector, was carried out by Ababil of Minab and took systems offline while defacing its website. The incident highlights the importance of understanding one’s own digital footprint.
The reaction to these incidents often falls into two extremes: either treating every claimed attack as an impending catastrophe or dismissing it as a minor inconvenience. However, both reactions miss something crucial. A seemingly unsophisticated attack may reveal weaknesses that could be exploited by more sophisticated threat actors with far worse consequences for the victim organization.
Operational technology (OT)-related incidents illustrate this problem perfectly. Attackers typically find their way into victim networks through old exploits or default credentials on externally exposed systems. While concerning, physical safety systems and engineering constraints limit what adversaries can actually do. So, they produce contextless screenshots of devices, post them on Telegram, and call it an “infrastructure attack.”
The weaknesses that enabled access in these incidents are not limited to the specific actors involved; more sophisticated threat actors with actual domain knowledge could follow the same initial access route and potentially do more serious damage. The information revealed by these low-sophistication intrusions is valuable in practical terms – it shows which environments are accessible, and this information doesn’t disappear once the hacktivist moves on.
To mitigate these risks, organizations need to take a proactive approach to managing their attack surface. This includes understanding what can be reached from the Internet within their environment, often different from internal asset inventories. Forgotten remote access points and unmanaged devices are common entry points that are easy to miss.
Authentication is also a critical component of cybersecurity. Default credentials and weak or absent multifactor authentication (MFA) remain among the most consistent contributing factors across these incidents. Implementing phishing-resistant MFA for anything externally accessible is a minimum requirement. By getting their house in order, organizations can reduce the attractiveness of their systems to opportunistic cyber actors and more effectively defend against sophisticated threat actors with malicious intent.
Source: Dark Reading — 2026-07-09