Also available in Persian — نسخه فارسی EN فا
❓ Unknown

Cybersecurity Researchers: Iranian-Attributed Hackers Used Two Malware in Defensive Attacks

Jan 23, 2026 January 23, 2026 1 min read 📰 Iran International (Farsi)
📋 Key Takeaway

Mandiant reported that a cyber group linked to Iran is employing two specific malware in attacks targeting key industries in the Middle East. This highlights the ongoing cyber threats posed by Iranian hackers, particularly in sensitive sectors.

🔍 Quick Context Guide
💡 Bottom Line: Iranian cyber attacks on critical industries underscore the growing threat of cyber warfare in the Middle East.

👥 Key Players

Mandiant MENTIONED
Cybersecurity company
"Mandiant is a leading cybersecurity firm that provides insights into cyber threats, particularly those linked to nation-states like Iran."
Islamic Republic of Iran MENTIONED
Nation-state actor
"Iran has been increasingly involved in cyber warfare, using hacking as a tool for geopolitical leverage and defense."

📰 What Happened

Mandiant reported that a group of hackers attributed to Iran has been using two types of malware, TWOSTROKE and DEEPROOT, to launch attacks on the aerospace, aviation, and defense sectors in the Middle East.

  • The malware TWOSTROKE and DEEPROOT are specifically designed for cyber attacks.
  • The targeted industries are critical for national security and economic stability in the region.

💡 Why It Matters

🇮🇷 For Iran: This highlights Iran's capabilities in cyber warfare and its focus on protecting its interests against perceived threats.
🌍 Regional: The attacks could escalate tensions in an already volatile region, impacting security and stability.
🌐 International: Western nations, particularly those involved in defense and cybersecurity, may view these attacks as a significant threat, prompting increased defensive measures.

📚 Background

Iran has been accused of engaging in cyber warfare as a means to project power and retaliate against adversaries, particularly in the context of geopolitical conflicts.

Cybersecurity Iran's geopolitical strategy
📡 Source: INTERNATIONAL
📊 Confidence: 70%
Mandiant is considered a reliable source in cybersecurity, but its reports may reflect a Western perspective on Iranian activities.

The cybersecurity company 'Mandiant', a subsidiary of Google, announced that a cyber group attributed to the Islamic Republic has used two malware, 'TWOSTROKE' and 'DEEPROOT', in ongoing attacks against aerospace, aviation, and defense industries in the Middle East.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →