Iran Accelerates Cyber Operations Against Israel

A picture published by Microsoft of the Iranian flag and above it digital symbols.
A picture published by Microsoft of the Iranian flag and above it digital symbols.
TT

Iran Accelerates Cyber Operations Against Israel

A picture published by Microsoft of the Iranian flag and above it digital symbols.
A picture published by Microsoft of the Iranian flag and above it digital symbols.

Since Hamas attacked Israel in October 2023, Iranian government-aligned actors have launched a series of cyberattacks and influence operations (IO) intended to help the Hamas cause and weaken Israel and its political allies and business partners, a report by Microsoft showed.

Iranian focus on Israel has intensified. The outbreak of the Israel-Hamas war saw 43% of Iranian nation-state cyber activity focused on Israel.

Many of Iran’s immediate operations after October 7 were hasty and chaotic – indicating it had little or no coordination with Hamas – but it nevertheless has achieved growing success.

The report also noted collaboration between Iran and a group affiliated with Hezbollah in Lebanon.

Iran will continue to test redlines, as they have done with an attack on an Israeli hospital and US water systems in late November.

As we look forward to the 2024 US presidential election, Iranian activities could build on what happened in 2020 when they impersonated American extremists and incited violence against US government officials.

Three phases of Iran’s cyber operations

Iran’s cyber-enabled operations in the Israel-Hamas war have moved through three phases since October 7.

Phase 1: Reactive and misleading

The first phase saw misleading claims from Iranian state media. One example was IRGC-affiliated Tasnim News Agency claiming that a group called “Cyber Avengers” had conducted cyberattacks against an Israeli power plant “at the same time” as the Hamas attacks. Cyber Avengers itself (also likely run by the IRGC) claimed to have attacked an Israeli electric company the evening before the Hamas attacks. However, its evidence was only some weeks-old press reporting of power outages “in recent years” and a screenshot of an undated disruption to the company’s website.

Phase 2: All hands on deck

Sometimes, multiple Iranian groups were targeting the same organization or military base in Israel with cyber or influence activity. This suggests coordination, common objectives set in Tehran, or both.

Iran’s 10 cyber-enabled operations against Israel in October marks a new high point. This was nearly double the previous high point of six operations per month in November 2022.

One example happened on October 18 when the IRGC’s Shahid Kaveh Group used customized ransomware to conduct cyberattacks against security cameras in Israel. It then used one of its cyber personas, “Soldiers of Solomon,” to falsely claim it had ransomed security cameras and data at Nevatim Air Force Base. Examination of the security footage Soldiers of Solomon leaked reveals it was from a town north of Tel Aviv with a Nevatim street, not the airbase of the same name.

Phase 3: Expanding geographic scope

In late November 2023, Iranian groups began expanding their cyber-enabled influence beyond Israel, targeting countries Iran perceives are supporting Israel. This aligned with the Iran-backed Houthis starting their attacks on international shipping.

On November 20, the MOIS-aligned cyber persona “Homeland Justice” warned of forthcoming cyberattacks on Albania. They later claimed credit for attacks on a range of Albanian organizations and institutions.

On November 21, the cyber persona “al-Toufan” targeted Bahraini government and financial organizations for normalizing ties with Israel.

By November 22, IRGC-affiliated groups began targeting Israeli-made programmable logic controllers (PLCs) in the United States, including taking one offline at a water authority in Pennsylvania on November 25. PLCs are industrial computers adapted for the control of manufacturing processes, such as assembly lines, machines, and robotic devices.

Since the outbreak of the Israel-Hamas war on October 7, Iran has increased its influence operations and hacking efforts against Israel. These attacks were reactive and opportunistic in the early days of the war but, by late October, nearly all of its influence and major cyber actors were targeting Israel.

Cyberattacks became increasingly targeted and destructive and IO campaigns grew increasingly sophisticated and inauthentic, deploying networks of social media “sockpuppet” accounts.

Iran’s activity quickly grew from nine Microsoft-tracked groups active in Israel during the first week of the war to 14, two weeks into the war. Cyber-enabled influence operations went from roughly one operation every other month in 2021 to 11 in October 2023 alone.

A 42% increase in traffic, in the first week of the war, to news sites run by or affiliated to the Iranian state. Even three weeks later, this traffic was still 28% above pre-war levels.

Iran’s objectives

Destabilization through polarization

Iran aims to exacerbate domestic political and social rifts in its targets, often focusing on the Israeli government’s approach to the 240 hostages taken by Hamas into Gaza and masquerading as peace-seeking activist groups criticizing the Israeli government. Israeli Prime Minister Netanyahu is the primary target of such messaging, often calling for his removal.

Retaliation

Many of Iran’s messaging and targets are explicitly retaliatory. The persona Cyber Avengers claimed it had targeted Israeli electricity, water, and fuel infrastructure in retaliation for Israel stating it would cut off electricity, water and fuel to Gaza and elsewhere referenced “an eye for an eye.”

Intimidation

Iran’s operations also aim to undermine Israeli security and intimidate Israel’s citizens and international supporters and threaten the families of Israeli army soldiers. Sockpuppet accounts spread messaging on X that the army “does not have any power to protect its own soldiers.” Other messaging, as in the example below, appears aimed at attempting to convince Israeli army soldiers to give up.

Undermining international support for Israel

Iranian Influence actors often include messaging that seeks to weaken international support for Israel by highlighting the damage caused by Israel’s attacks on Gaza.

Iran AI-generated attacks

In early December 2023, Iran interrupted streaming television services and replaced them with a fake news video featuring an apparently AI-generated news anchor. This marked the first Iranian influence operation Microsoft has detected where AI played a key component in its messaging and is one example of the fast and significant expansion in the scope of Iranian operations since the start of the Israel-Hamas conflict. The disruption reached audiences in the UAE, UK, and Canada.

Microsoft’s AI for Good Lab’s Iranian Propaganda Index (IPI) monitors the proportion of traffic visiting Iranian state and state-affiliated news outlets and amplifiers compared to overall traffic on the internet.

In the first week of the conflict, we observed a 42% increase. That surge was particularly pronounced in the United States and its English-speaking allies (UK, Canada, Australia, and New Zealand), which indicates Iran’s ability to reach Western audiences with its reporting on Middle East conflicts.

While this success was strongest in the early days of the war, the reach of these Iranian sources one month into the war remained 28% above pre-war levels globally.

Trends in Iranian influence operations

Impersonation is not new, but Iranian threat actors are now not just masquerading as their enemies but also their friends. Recent operations from Iranian groups have used the name and logo of Hamas’s military wing, the al-Qassam Brigades, to spread false messaging and threaten Israeli army personnel. It is unclear whether Iran is acting with Hamas’s consent.

Iran has managed to repeatedly recruit unwitting Israelis to engage in on-the-ground activities promoting its false operations. In one recent operation, “Tears of War,” Iranian operatives convinced Israelis to hang branded Tears of War banners using AI-generated images in Israeli neighborhoods, based on Israeli press reporting. A Tears of War banner with an image of Netanyahu that is likely AI-generated. The banner’s text reads “Impeachment now.”

Iran’s use of bulk text message and email campaigns has grown in order to enhance the psychological effects of their cyber-enabled influence operations. Messages appearing on people’s phones or in their inboxes have more impact than sockpuppet accounts on social media. Iran uses overt and covert IRGC-linked media outlets to amplify alleged cyber operations and, at times, exaggerate their effects. In September, after Cyber Avengers claimed cyberattacks against Israel’s railway system, IRGC-linked media almost immediately amplified and exaggerated their claims.



Trump Refuses to Apologize for Video Depicting Obama and Wife as Apes

FILE PHOTO: US President Donald Trump and first lady Melania Trump see off former US President Barack Obama and his wife Michelle Obama as they depart following Trump's inauguration at the Capitol in Washington, US January 20, 2017. REUTERS/Jonathan Ernst/File Photo
FILE PHOTO: US President Donald Trump and first lady Melania Trump see off former US President Barack Obama and his wife Michelle Obama as they depart following Trump's inauguration at the Capitol in Washington, US January 20, 2017. REUTERS/Jonathan Ernst/File Photo
TT

Trump Refuses to Apologize for Video Depicting Obama and Wife as Apes

FILE PHOTO: US President Donald Trump and first lady Melania Trump see off former US President Barack Obama and his wife Michelle Obama as they depart following Trump's inauguration at the Capitol in Washington, US January 20, 2017. REUTERS/Jonathan Ernst/File Photo
FILE PHOTO: US President Donald Trump and first lady Melania Trump see off former US President Barack Obama and his wife Michelle Obama as they depart following Trump's inauguration at the Capitol in Washington, US January 20, 2017. REUTERS/Jonathan Ernst/File Photo

President Donald Trump’s racist social media post featuring former President Barack Obama and his wife, Michelle Obama, as primates in a jungle was deleted Friday after a backlash from both Republicans and Democrats who criticized the video as offensive.

Trump said later Friday that he won't apologize for the post: “I didn't make a mistake,” he said.

The Republican president’s Thursday night post was blamed on a staffer after widespread backlash, from civil rights leaders to veteran Republican senators, for its treatment of the nation’s first Black president and first lady. A rare admission of a misstep by the White House, the deletion came hours after press secretary Karoline Leavitt dismissed “fake outrage” over the post. After calls for its removal — including by Republicans — the White House said a staffer had posted the video erroneously.

The post was part of a flurry of overnight activity on Trump's Truth Social account that amplified his false claims that the 2020 election was stolen from him, despite courts around the country and Trump's first-term attorney general finding no evidence of systemic fraud.

Trump has a record of intensely personal criticism of the Obamas and of using incendiary, sometimes racist, rhetoric — from feeding the lie that Obama was not a native-born US citizen to crude generalizations about majority-Black countries.

The post came in the first week of Black History Month and days after a Trump proclamation cited “the contributions of black Americans to our national greatness” and “the American principles of liberty, justice, and equality.”

An Obama spokeswoman said the former president, a Democrat, had no response.

‘An internet meme’

Nearly all of the 62-second clip appears to be from a conservative video alleging deliberate tampering with voting machines in battleground states as 2020 votes were tallied. At the 60-second mark is a quick scene of two jungle primates, with the Obamas’ smiling faces imposed on them.

Those frames originated from a separate video, previously circulated by an influential conservative meme maker. It shows Trump as “King of the Jungle” and depicts Democratic leaders as animals, including Joe Biden, who is white, as a jungle primate eating a banana.

“This is from an internet meme video depicting President Trump as the King of the Jungle and Democrats as characters from the Lion King,” Leavitt said by text.

Disney's 1994 feature film that Leavitt referenced is set on the savannah, not in the jungle, and it does not include great apes.

“Please stop the fake outrage and report on something today that actually matters to the American public,” Leavitt added.

By noon, the post had been taken down, with responsibility placed on a Trump subordinate.

Trump, answering questions from reporters accompanying him Friday night aboard Air Force One, said the video was about fraudulent elections and that he liked what he saw.

“I liked the beginning. I saw it and just passed it on, and I guess probably nobody reviewed the end of it,” he said.

Asked if he condemned the video's racism, Trump said, “Of course I do.”

The White House explanation raises questions about control of Trump’s social media account, which he's used to levy import taxes, threaten military action, make other announcements and intimidate political rivals. The president often signs his name or initials after policy posts.

The White House did not immediately respond to an inquiry about how posts are vetted and when the public can know when Trump himself is posting.

Mark Burns, a pastor and a prominent Trump supporter who is Black, said Friday on X that he'd spoken “directly” with Trump and that he recommended to the president that he fire the staffer who posted the video and publicly condemn what happened.

“He knows this is wrong, offensive, and unacceptable,” Burns posted.

Congressional Black Caucus Chairwoman Yvette Clarke, D-N.Y., told The Associated Press she does “not buy the White House's commentary.”

Condemnation across the political spectrum Trump and White House social media accounts frequently repost memes and artificial intelligence-generated videos. As Leavitt did Friday, Trump allies typically cast them as humorous.

This time, condemnations flowed from across the spectrum — along with demands for an apology that doesn't appear to be coming.


Clintons Call for Their Epstein Testimony to Be Public

Images of former US President Bill Clinton are on display as Chairman of the House Oversight Committee James Comer (R-KY) speaks during a meeting to vote on whether to hold Clinton and former Secretary of State Hillary Clinton in contempt of Congress for defying subpoenas to testify in the panel's investigation of the late convicted offender Jeffrey Epstein, on Capitol Hill in Washington, D.C., US, January 21, 2026. REUTERS/Kevin Lamarque
Images of former US President Bill Clinton are on display as Chairman of the House Oversight Committee James Comer (R-KY) speaks during a meeting to vote on whether to hold Clinton and former Secretary of State Hillary Clinton in contempt of Congress for defying subpoenas to testify in the panel's investigation of the late convicted offender Jeffrey Epstein, on Capitol Hill in Washington, D.C., US, January 21, 2026. REUTERS/Kevin Lamarque
TT

Clintons Call for Their Epstein Testimony to Be Public

Images of former US President Bill Clinton are on display as Chairman of the House Oversight Committee James Comer (R-KY) speaks during a meeting to vote on whether to hold Clinton and former Secretary of State Hillary Clinton in contempt of Congress for defying subpoenas to testify in the panel's investigation of the late convicted offender Jeffrey Epstein, on Capitol Hill in Washington, D.C., US, January 21, 2026. REUTERS/Kevin Lamarque
Images of former US President Bill Clinton are on display as Chairman of the House Oversight Committee James Comer (R-KY) speaks during a meeting to vote on whether to hold Clinton and former Secretary of State Hillary Clinton in contempt of Congress for defying subpoenas to testify in the panel's investigation of the late convicted offender Jeffrey Epstein, on Capitol Hill in Washington, D.C., US, January 21, 2026. REUTERS/Kevin Lamarque

Former US president Bill Clinton and his wife Hillary are calling for their congressional testimony on ties to convicted sex trafficker Jeffrey Epstein to be held publicly, to prevent Republicans from politicizing the issue.

Both Clintons had been ordered to give closed-door depositions before the House Oversight Committee, which is probing the deceased financier's connections to powerful figures and how information about his crimes was handled, said AFP.

Democrats say the probe is being weaponized to attack political opponents of President Donald Trump -- himself a longtime Epstein associate who has not been called to testify -- rather than to conduct legitimate oversight.

House Republicans had previously threatened a contempt vote if the Democratic power couple did not show up to testify, which they have since agreed to do.

But holding the deposition behind closed doors, Bill Clinton said Friday, would be akin to being tried at a "kangaroo court."

"Let's stop the games & do this the right way: in a public hearing," the former Democratic president said on X.

Hillary Clinton, former secretary of state, said the couple had already told the Republican-led Oversight Committee "what we know."

"If you want this fight...let's have it in public," she said Thursday.

The Justice Department last week released the latest cache of so-called Epstein files -- more than three million documents, photos and videos related to its investigation into Epstein, who died from what was determined to be suicide while in custody in 2019.

Bill Clinton features regularly in the files, but no evidence has come to light implicating either Clinton in criminal activity.

The former president has acknowledged flying on Epstein's plane in the early 2000s for Clinton Foundation-related humanitarian work, but said he never visited Epstein's private island.

Hillary Clinton, who ran against Trump for president in 2016, said she had no meaningful interactions with Epstein, never flew on his plane and never visited his island.


Two Airports in Poland Closed Due to Russian Strikes on Ukraine

Lublin Airport is unavailable due to military activity involving NATO aircraft (Reuters)
Lublin Airport is unavailable due to military activity involving NATO aircraft (Reuters)
TT

Two Airports in Poland Closed Due to Russian Strikes on Ukraine

Lublin Airport is unavailable due to military activity involving NATO aircraft (Reuters)
Lublin Airport is unavailable due to military activity involving NATO aircraft (Reuters)

Two airports in southeastern Poland were suspended from operations as a precaution due to Russian strikes on nearby Ukraine territory, Polish authorities said on Saturday.

"In connection with the need to ensure the possibility of the free operation of military aviation, the airports in Rzeszow and Lublin ‌have temporarily ‌suspended flight operations," ‌Polish Air ⁠Navigation Services Agency ‌posted on X.

Both cities are close to the country's border with Ukraine, with Rzeszow being NATO's main hub for arms supplies to Ukraine, Reuters said.

Military aviation had begun operating in Polish airspace due to Russian ⁠strikes on Ukraine, the Operational Command of ‌the Polish Armed Forces said on ‍X.

"These actions are ‍of a preventive nature and ‍are aimed at securing and protecting the airspace, particularly in areas adjacent to the threatened regions," the army said.

Flight tracking service FlightRadar24 posted on X that the closure involved NATO aircraft operating in the area.

The ⁠US Federal Aviation Administration said in a notice to airmen that both airports were inaccessible due to the military activity related to ensuring state security.

Last month, Rzeszow and Lublin suspended operations for a time, but the authorities said then that the military aviation operations were routine and there had been no threat to ‌Polish airspace.