Skip to main content
Suzu Logo
  • Home
  • Products
  • Services
    • Offensive Security
    • Defensive Security
    • AI Advisory
    • AI Assessment
    • AI Integration
  • About
    • About Us
    • FAQ's
  • Resources
    • Blog
    • In The Media
    • Podcasts
    • All Resources
Contact Us
Back to Blog
Critical Infrastructure Threat Intelligence Cybersecurity Cyber Escalation Cyber Attacks Cyber Defense

From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time

Denis Calderone March 13, 2026 7 min read
Table of Contents

    On March 12, medical technology giant Stryker confirmed a cyberattack that wiped devices across 79 countries. The pro-Iran group Handala claimed responsibility, saying they destroyed more than 200,000 systems and stole 50 terabytes of data. Stryker manufactures surgical tools and implants used by hospitals worldwide, holds DOD contracts, and acquired Israeli medical
    tech firm OrthoSpace in 2019.

    In the weeks leading up to the war, what concerned us wasn't the groups making noise. It was the ones that had gone quiet.

    What The Silence Told Us

    The signs were there before the kinetic strikes even started. Symantec research later confirmed that MuddyWater, a group CISA has called a subordinate element within Iran's Ministry of Intelligence and Security, had been active on US networks since early February. They were on the networks of a US bank, a US airport, and a defense-aerospace software supplier, with the software company's Israeli operations appearing to be the specific target. The group had deployed a brand-new backdoor called Dindoor that nobody had seen before, signed with stolen certificates and using legitimate cloud storage for exfiltration. Everything built to look like normal business traffic. This was weeks before the February 28 strikes.

    On March 2, when the conversation was mostly about DDoS and ransomware as the expected retaliation playbook, we couldn’t help but notice that Iran's most capable espionage groups had gone quiet during the biggest crisis in their country's modern history. It seemed reasonable to think that silence probably meant pre-positioning, not inactivity, and urged organizations in energy, financial services, defense, and healthcare to start hunting for anomalous access. This would be proven out four days later when Symantec confirmed what MuddyWater was up to.

    Then came Stryker. A Fortune 500 US company with Israeli business ties, hit not with espionage tools but with a destructive wiper. The shift from intelligence gathering to destruction was underway.

    Two Groups, One Target Profile

    Both MuddyWater and Handala are tied to Iran's Ministry of Intelligence and Security, but they do very different things. 

    MuddyWater, also known as Seedworm, has been around since 2017. They build custom tooling, run spear-phishing campaigns, and focus on getting persistent access for intelligence collection. In this campaign, they deployed at least three distinct backdoors and used Rclone to push stolen data to Wasabi and Backblaze cloud storage. Stolen certificates to sign malware, legitimate cloud services for command and control. Everything looks normal until you trace the full sequence. 

    Handala is the other side of the coin. On the surface they look like a hacktivist group aligned with pro-Palestine sentiment, but the cybersecurity community widely assesses them as a front for Void Manticore, another MOIS-linked actor. Destruction is their thing. Custom wiper malware for Windows and Linux. Before Stryker, they went after Israeli military weather servers, healthcare networks, oil and gas companies, and sent fake missile alerts to Israeli schools. 

    Here's the part that should concern defenders: the espionage groups go in first and map the environment, then the destructive groups follow. MuddyWater was already inside US networks before the kinetic strikes landed on February 28. Handala came in swinging after.

    The Inherited Trust Problem

    How Handala hit Stryker matters as much as the fact that they hit them. Based on employee reports and now confirmed by multiple researchers including Brian Krebs, Handala got into Stryker's Microsoft Intune environment and used the platform's own capabilities to remotely wipe every enrolled device. Laptops, servers, corporate phones, even employees' personal devices that were connected to corporate systems. No malware needed. They used the native features of an enterprise management tool to cause destruction at scale. Stryker's SEC filing confirmed "no indication of ransomware or malware." The management platform did the
    damage.

    As we write this, the situation keeps getting worse. Stryker has confirmed that order processing, manufacturing, and shipping have all been disrupted, with no timeline for full restoration. Thousands of employees across Ireland, the US, Australia, and India are locked out. For a company that makes surgical tools and implants used in operating rooms around the world, this goes well beyond IT. Hospitals that depend on Stryker's products are feeling it right now.

    We've been watching this same dynamic play out across multiple incidents in 2026. VMware Aria Operations, Cisco Secure Firewall Management Center, Cisco SD-WAN controllers, and now MDM. We've started calling it the inherited trust problem. Management and orchestration tools carry the deepest access in your environment because that's how they're designed to work. MDM platforms can factory reset every device in your fleet. Firewall management consoles can rewrite your security policies. When attackers take over the management plane, the tool does
    the damage for them.

    What Comes Next

    This campaign is not over. Threat intelligence analysts are projecting Iranian cyber operations to continue through mid-April, with more destructive attacks expected as Iran's operational capabilities recover from the initial internet disruption. More than 60 hacktivist groups spun up within hours of the February 28 strikes. During the June 2025 Twelve-Day War, cyberattacks surged 700% within 48 hours. We've seen how fast this can escalate.

    We're watching three things closely right now. 

    OT and industrial control systems. CyberAv3ngers, an IRGC-affiliated group that hit US water utilities in 2023, has since deployed a custom OT malware called IOCONTROL that can target PLCs, HMIs, and IoT devices from Siemens, Allen-Bradley, Schneider Electric, and others. An IRGC-linked offensive OT framework called Black Industry has shown up on dark web markets with capabilities including multi-protocol scanning, PLC persistence, and air-gap penetration tools. There are roughly 40,000 internet-exposed ICS devices in the United States, many at water utilities and energy facilities running on tight budgets. Wiper attacks on IT environments may be the opening salvo. OT is where it gets really dangerous.

    Supply chain and managed service provider compromise. MuddyWater's targeting of a defense- aerospace software supplier wasn't just about that company. It was about what that company connects to. Iranian groups have a documented track record of using third-party vendors and MSPs as doorways into larger organizations. You don't need Israeli business ties to be in scope. You just need to serve someone who does.

    Iran's internet workaround. Domestic connectivity dropped to 1-4% of normal capacity after the strikes, but that hasn't stopped anything. Handala was reportedly using Starlink satellite connectivity before the current conflict even began. Pre-positioned implants and operators based outside Iran keep working regardless of what happens to domestic infrastructure. The idea that Iran going dark limits their offensive capability has already been put to rest.

    What Defenders Should Do Now

    If your organization has Israeli business ties, DOD contracts, or sits anywhere in the defense, healthcare, energy, or financial services supply chain, treat this as a heightened threat period.

    Go through your management tools: MDM, firewall management consoles, infrastructure
    monitoring, workflow automation. Can a single compromised admin account wipe your fleet or rewrite your security policies? If the answer is yes, or you're not sure, that's the first thing to fix. These tools have the deepest access in your environment, and Stryker just showed us what happens when they're turned against you.

    Hunt for anomalous access going back to early February. MuddyWater was already inside before the shooting started. Look for unexpected cloud storage connections, especially to Wasabi and Backblaze. Check for certificates you didn't issue. Watch for unusual data volumes heading outbound.

    If you run OT or ICS environments, don't assume the air gap will save you. Review segmentation between IT and OT. Check whether your PLCs are still on default credentials. Make sure your HMIs aren't reachable from the internet.

    Make sure your backups are isolated and tested. Wiper attacks don't come with a
    decryption key. Your ability to get back up and running depends entirely on whether your
    backup infrastructure is separated from everything that just got wiped.

    The pre-positioning phase is over. We're in the execution phase now, and based on what we're seeing, it's going to get worse before it gets better. Start hunting now. Don't wait for something to break.

    Share
    Tags: Critical Infrastructure Threat Intelligence Cybersecurity Cyber Escalation Cyber Attacks Cyber Defense
    Denis Calderone
    Denis Calderone

    As CTO of Suzu Labs, Denis Calderone draws on over 30 years of IT experience and 25 years in information security. He founded and led a security consultancy for over 17 years before its global acquisition, and now channels that experience into Suzu Labs, where he sets technical direction while overseeing cyber delivery, including penetration testing and a full host of advisory services. His approach is vendor-agnostic and operationally grounded, cutting through noise to deliver practical, sustainable risk management. He pairs deep industry expertise with early AI adoption to ensure security is built-in, not bolted on.

    Stay ahead of the threat landscape

    AI security insights, threat intelligence, and research from our team. No spam, unsubscribe anytime.

    Subscribe
    ← Previous Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation Next → Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss

    Latest Posts

    View All
    When Elite Cyber Teams Can't Crack Web Security
    Cybersecurity
    Apr 23, 2026 Jacob Krell

    When Elite Cyber Teams Can't Crack Web Security

    HTB's 2025 benchmark tested 796 security teams. Only 21% passed web security challenges. The Security Illusion Security ...

    Read More: When Elite Cyber Teams Can't Crack Web Security
    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Cybersecurity
    Apr 22, 2026 Jacob Krell

    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them

    In today's security landscape, some of the most dangerous vulnerabilities aren't flagged by automated scanners at all. ...

    Read More: The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Suzu Labs Acquires Emulated Criminals
    Apr 20, 2026 Hannah Perez

    Suzu Labs Acquires Emulated Criminals

    Bridging the gap between theory and the threat reality, Suzu Labs is proud to announce the acquisition of Emulated ...

    Read More: Suzu Labs Acquires Emulated Criminals
    The Wall Around Claude 4.7 Does Not Extend to Dread
    Cybersecurity
    Apr 17, 2026 Suzu Labs

    The Wall Around Claude 4.7 Does Not Extend to Dread

    Anthropic released Claude Opus 4.7 on April 16, 2026 with automated cybersecurity safeguards and a Cyber Verification ...

    Read More: The Wall Around Claude 4.7 Does Not Extend to Dread
    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    youtube
    Apr 10, 2026 Jacob Krell

    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control

    Earlier this year, YouTube began rolling out a row of algorithmically recommended videos at the top of the ...

    Read More: The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    The AI Revolution: How Jobs Will Change by 2030
    Cybersecurity
    Apr 07, 2026 Suzu Labs

    The AI Revolution: How Jobs Will Change by 2030

    Host Phillip Wylie sits down with Nicolas Chaillan to discuss the sobering reality of AI replacement, the critical need ...

    Read More: The AI Revolution: How Jobs Will Change by 2030
    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    Generative AI
    Apr 01, 2026 Hannah Perez

    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?

    In late 2024, Sydney tech entrepreneur Paul Conyngham was told his rescue dog, Rosie, had months to live. She was ...

    Read More: The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    Cybersecurity
    Mar 30, 2026 Suzu Labs

    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone

    The world of cybersecurity has undergone a massive transformation in just a few decades. In this episode of Simply ...

    Read More: From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    While TSA Made Headlines, CISA Went Dark
    Critical Infrastructure
    Mar 30, 2026 Jacob Krell

    While TSA Made Headlines, CISA Went Dark

    The Department of Homeland Security has been partially shut down for over 45 days. In that time, 460 TSA officers have ...

    Read More: While TSA Made Headlines, CISA Went Dark
    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    AI Security
    Mar 30, 2026 Suzu Labs

    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks

    In cybersecurity, we often operate in silos. The red team breaks things, the blue team fixes them, and management ...

    Read More: The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    Claude Mythos and the Cybersecurity Risk That Was Already Here
    Threat Intelligence
    Mar 27, 2026 Jacob Krell

    Claude Mythos and the Cybersecurity Risk That Was Already Here

    On March 26, Anthropic confirmed the existence of Claude Mythos, an unreleased AI model described internally as "a step ...

    Read More: Claude Mythos and the Cybersecurity Risk That Was Already Here
    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Critical Infrastructure
    Mar 26, 2026 Mike Bell

    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It

    Rapid7's research reveals China-linked kernel implants deep inside telecom signaling infrastructure. Here's what ...

    Read More: BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    Cybersecurity
    Mar 23, 2026 Hannah Perez

    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026

    We are incredibly proud to announce a monumental achievement. At this year’s Global InfoSec Awards 2026, hosted by ...

    Read More: Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Cybersecurity
    Mar 17, 2026 Suzu Labs

    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity

    In the world of cybersecurity, we often talk about "gatekeeping" or the "skills gap," but rarely do we find individuals ...

    Read More: From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    Cybersecurity
    Mar 16, 2026 Phillip Wylie

    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss

    The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss In this episode of Simply Offensive, ...

    Read More: Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Critical Infrastructure
    Mar 13, 2026 Denis Calderone

    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time

    On March 12, medical technology giant Stryker confirmed a cyberattack that wiped devices across 79 countries. The ...

    Read More: From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    Social Engineering
    Mar 09, 2026 Suzu Labs Intelligence

    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation

    Executive Summary Even Realities markets its G2 smart glasses as the privacy-conscious alternative to Meta Ray-Bans. ...

    Read More: Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    Threat Intelligence
    Mar 06, 2026 Mike Bell

    The Company Reviewing Your Meta Glasses Footage Has a Security Problem

    Last week, Swedish journalists revealed that Meta sends video footage from Meta Ray-Ban smart glasses to human data ...

    Read More: The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    CTF
    Mar 03, 2026 Jacob Krell

    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

    View White Paper Abstract: Agentic AI systems are compressing competitive hacking timelines faster than the ...

    Read More: The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Cybersecurity
    Mar 03, 2026 Phillip Wylie

    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell

    In this thought-provoking episode of Simply Offensive, host Philip Wylie sits down with Jacob Krell, a penetration ...

    Read More: Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Anthropic and Claude: 2026 AI Powerhouse
    Supply Chain Security
    Feb 26, 2026 Hannah Perez

    Anthropic and Claude: 2026 AI Powerhouse

    In early 2026, the image of Anthropic as a cautious, safety-oriented "research lab" has effectively been replaced by ...

    Read More: Anthropic and Claude: 2026 AI Powerhouse
    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Cybersecurity
    Feb 24, 2026 Phillip Wylie

    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle

    In this episode of Simply Offensive, host Philip Wylie welcomes Darius Houle, an Application Security (AppSec) and ...

    Read More: Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Cybersecurity
    Feb 17, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown

    In the latest episode of the Simply Offensive podcast, host Philip Wylie sat down with Matt Brown, a renowned hardware ...

    Read More: Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Cybersecurity
    Feb 12, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs

    In today’s rapidly evolving technological landscape, the convergence of artificial intelligence (AI) and cybersecurity ...

    Read More: Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Threat Intelligence
    Feb 10, 2026 Phillip Wylie

    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss

    Beyond the Pentest: Why Adversarial Emulation is the Future of Defensive Training Many organizations operate under the ...

    Read More: Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Under Armour Breach: What The Forum Data Actually Shows
    Threat Intelligence
    Jan 30, 2026 Mike Bell

    Under Armour Breach: What The Forum Data Actually Shows

    On January 18, 2026, the Everest ransomware group made good on their threat and released Under Armour customer data to ...

    Read More: Under Armour Breach: What The Forum Data Actually Shows
    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Briefing Room
    Jan 29, 2026 Dahvid Schloss

    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers

    This article is in reference to our newest POC hosted on GitHub here: https://github.com/Emulated-Criminals/SilentFrame ...

    Read More: SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Brightspeed Breach: Crimson Collective and the Infostealer Problem
    Threat Intelligence
    Jan 20, 2026 Mike Bell

    Brightspeed Breach: Crimson Collective and the Infostealer Problem

    Recently Crimson Collective claimed they breached Brightspeed and grabbed 1 million+ customer records. The list of data ...

    Read More: Brightspeed Breach: Crimson Collective and the Infostealer Problem
    When Grid Data Goes Dark Web
    Power Grid
    Jan 19, 2026 Mike Bell

    When Grid Data Goes Dark Web

    Inside a threat actor's critical infrastructure targeting In January 2026, 139 gigabytes of engineering data from a ...

    Read More: When Grid Data Goes Dark Web
    The $150,000 Password
    Critical Infrastructure
    Jan 19, 2026 Mike Bell

    The $150,000 Password

    How one threat actor turned stolen credentials into a global breach portfolio Between December 2025 and January 2026, a ...

    Read More: The $150,000 Password
    Seeing Everything, Understanding Nothing
    Briefing Room
    Jan 16, 2026 Dahvid Schloss

    Seeing Everything, Understanding Nothing

    To help you get a head start on making your environment safer and in keeping with the theme of January’s “New Year, New ...

    Read More: Seeing Everything, Understanding Nothing
    New Year, New Priorities - So, what to fix first?
    Briefing Room
    Jan 08, 2026 Dahvid Schloss

    New Year, New Priorities - So, what to fix first?

    The most common phrase we hear from our prospects is, “We are overwhelmed, and we aren’t sure what to tackle first.” ...

    Read More: New Year, New Priorities - So, what to fix first?
    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Briefing Room
    Nov 21, 2025 Dahvid Schloss

    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)

    Repository purpose: this research was to evaluate the feasiabilty of using Alternate Data Stream (ADS) in staging and ...

    Read More: UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Logo copy 3-1

    Fortified Security. Intelligent Innovation.

    +1 (702) 766-6257
    P.O. Box 750111
    Las Vegas, Nevada 89136

    Follow Us

    About

    • About Us
    • Contact
    • FAQ's

    Solutions

    • Products
    • AI Advisory
    • AI Assessment
    • Offensive Security
    • Defensive Security
    • Adversarial Operations
    • Social Engineering

    Resources

    • Blog
    • In The Media
    • Podcasts
    © 2026 All rights reserved.
    • Privacy Policy
    • Terms & Conditions