Header image

Session 3.4b Update: A Look at Modern Iranian Hybrid Cyber Operations

Tracks
Thursday, November 19, 2026
11:30 AM - 12:30 PM
Bradman Theatre

Presentation Outline

Iranian threat groups have increasingly blended espionage, destructive malware, and influence operations into coordinated hybrid campaigns, and the period spanning Q2 2025 through Q2 2026 offers a sharp window into this evolution. As a Five Eyes (FVEY) partner, Australia has a direct stake in understanding Iranian hybrid operations, as campaigns of this nature have demonstrated the capacity to pivot from regional targets to allied nations' diplomatic, defense, and critical infrastructure networks. Recorded Future's Insikt Group will present findings from a multi-cluster tracking effort illustrating how these groups coordinate infrastructure, tooling, and targeting across concurrent operations. At the center of this activity are three interconnected Iranian threat clusters: GreenHotel (Cotton Sandstorm), TAG-175, and TAG-143. GreenHotel forms the operational core; its infrastructure, operationalized as early as Q2 2025, remained active until Operation Epic Fury. Insikt Group identified large-scale reconnaissance scanning, open attacker-controlled directories hosting offensive tooling, curated target lists, exploit scripts, and lure documents. GreenHotel likely exploited multiple vulnerabilities affecting Hikvision web servers, SmarterMail, Windows Update mechanisms, and Cisco networking devices, while deploying its custom malware, WezRat. TAG-175, associated with the dual-use espionage and destructive malware GigaWiper, operates in parallel with GreenHotel via a suspected shared front entity, Cyber Isnaad Front. TAG-143, focused on PLC targeting and likely attributable to another Iran-nexus group, Cyber Av3ngers, is connected to TAG-175 through a likely custom VPN network of unknown ownership. While attribution of the VPN infrastructure remains inconclusive, its use across these clusters points to likely shared resourcing within the broader Iranian cyber ecosystem.


Speaker

Agenda Item Image
Mr Daryush Baudo
Principal Threat Intelligence Analyst
Recorded Future

Biography

Daryush has over 15 years of experience in security and intelligence covering Iranian and thematic threats impacting the Middle East. In the cyber domain, Daryush has tracked various operational and strategic developments tied to Iranian APTs during his time at Recorded Future. Prior to Recorded Future, Daryush worked for CrowdStrike and, before that, for American International Group and the Australian Federal Government.
loading