Cyber Isnaad Front: The Destructive IT/OT Convergence in Israeli Critical Sectors
- Actor Motivations: Exfiltration,Sabotage
- Attack Vectors: Security Misconfiguration,Vulnerability Exploitation,Malware,Ransomware,RAT,Trojan,Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
An Iranian state-directed persona, Cyber Isnaad Front (linked to IRGC-affiliated ASA), has been conducting destructive cyber operations against Israeli industry under the cover of a kinetic ceasefire. Targeting the defense, telecom, logistics, and food production sectors, the actor demonstrates a dangerous convergence of IT and OT capabilities. On IT networks, they deploy the Go Remote Access Toolkit (GRAT) disguised as Microsoft updates to execute devastating disk wipes. Concurrently, in OT environments, the attackers perform deep physical sabotage, such as reprogramming industrial CO2 refrigeration controllers to destroy mechanical compressors. This campaign leverages a hack-and-leak facade to obscure its true intent: deniable physical and digital destruction.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Sector | Food and Agriculture | Verified |
| Sector | Logistics | Verified |
| Sector | Telecommunication | Verified |
| Region | Israel | Verified |
Extracted IOCs
- 0ad128e813314e4562489478e6def8c6dfcc251e006d7f55b24273e93d3bc7fb
- 6f5f427d96656ae51405e6a5e65253759db45ea0a17da2d70f881404a4ed717b
- 86194eb5c5abcfe763899aaad7eb64894c71e816dd7d27427c8bac4ab280533d
- c4909b2d7a7f813b5a3d729fe64535033e716ae89dc39c402a6cb8ccbccaadca
- 146[.]103.40.190
- 193[.]29.104.5
- 45[.]82.66.163
- 84[.]201.6.128
- 84[.]201.6.129
- 84[.]201.6.131
- 85[.]137.56.9
- 85[.]17.55.232
Tip: 12 related IOCs (8 IP, 0 domain, 0 URL, 0 email, 4 file hash) to this threat have been found.
FAQs
Understanding the Cyber Isnaad Front Infrastructure Attacks
Threat actors breached the computer networks and industrial machinery of a food-production plant. They planted malicious software designed to permanently erase business computers and actively reprogrammed the facility's refrigeration equipment to overheat and physically destroy itself.
The attacks are attributed to "Cyber Isnaad Front," an operation directed by the Iranian state and affiliated with the Islamic Revolutionary Guard Corps (IRGC). While they publicly pretend to be an independent hacktivist group, they are actually a highly coordinated government team previously known for international election interference.
The primary goal was physical destruction and operational sabotage, not just stealing data. By breaking the business computers and destroying the physical machinery that runs the facility, the attackers intended to maximize downtime, cause expensive damage, and disrupt essential services.
This specific incident is part of a much broader, ongoing campaign occurring throughout 2025 and 2026. The threat actors are using periods of geopolitical ceasefire as a quiet cover to systematically infiltrate and compromise industrial networks.
Yes, the attackers specifically focused on unglamorous but critical infrastructure sectors within Israel. The targeted resources include defense supply chains, telecommunications centers, fuel logistics providers, and food production facilities.
The attackers initially broke in through internet-connected portals like VPNs. Once inside the business network, they hid destructive software disguised as routine Microsoft updates. They then crossed into the industrial network, locked out the actual facility engineers, and manually disabled the safety limits on the machinery so it would catastrophically fail.
These physical industries are the backbone of what a population relies on to stay fed, fueled, and connected. Sabotaging them causes immense, real-world disruption for civilians, all while keeping the political visibility and consequences much lower than a traditional military strike.
Organizations must ensure that the computers managing their business are digitally disconnected from the computers managing their physical machinery. They should also closely monitor who has remote access to factory equipment, keep secure offline backups of their machinery's programming, and immediately update their internet-facing security portals.
This is a highly targeted campaign directed specifically at critical infrastructure and supply chains within Israel. However, the advanced methods used—especially the ability to jump from business computers to destroying physical machinery, serve as a severe warning for any organization worldwide running industrial equipment.