Also available in Persian — نسخه فارسی EN فا
🔴 Breaking ❓ Unknown

Microsoft: Prominent Middle Eastern Experts Targeted by Islamic Republic Hackers

Jul 6, 2026 July 6, 2026 3 min read 📰 VOA Persian
📋 Key Takeaway

Microsoft reported that hackers linked to the Islamic Republic are targeting prominent Middle Eastern experts in various countries through phishing attacks. This highlights the ongoing cyber threats posed by Iranian hackers, particularly in the context of geopolitical tensions. The implications of these attacks raise concerns about the security of sensitive information related to political and security issues.

🔍 Quick Context Guide
💡 Bottom Line: Iranian hackers are actively targeting experts to gather intelligence on security and political perspectives.

👥 Key Players

Mint Sandstorm ACTOR
Hacking group
"A subgroup of a hacking group called 'Mint Sandstorm' has been targeting these experts since November."
Microsoft QUOTED
Technology company
"Microsoft has announced in a new report that prominent regional experts in the Middle East... have been targeted."
Hezbollah ACTOR
Terrorist group
"A cyberattack in November led by Tehran and the terrorist group Hezbollah targeted the Ziv Medical Center."
Islamic Republic hackers ACTOR
Cyber attackers
"Hackers believed to be linked to the Islamic Republic and centers in Tehran."

⚡ Actions

Mint Sandstorm ATTACK prominent regional experts
"A subgroup of a hacking group called 'Mint Sandstorm' has been targeting these experts since November using a phishing scheme."
Confidence: 90%
Microsoft ANNOUNCE public
"Microsoft has announced in a new report that prominent regional experts in the Middle East... have been targeted by hackers believed to be linked to the Islamic Republic."
Confidence: 90%
Islamic Republic hackers ATTACK Ziv Medical Center in Safed
"A cyberattack in November led by Tehran and the terrorist group Hezbollah targeted the Ziv Medical Center in Safed."
Confidence: 90%

📰 What Happened

Iranian hackers targeted Middle Eastern experts globally, using phishing schemes linked to Tehran.

  • Mint Sandstorm attack prominent regional experts
  • Microsoft announce public
  • Islamic Republic hackers attack Ziv Medical Center in Safed

💡 Why It Matters

🇮🇷 For Iran: Because it targets individuals with insights on security and political issues of interest to Tehran.
🌍 Regional: Because it reflects Iran's ongoing cyber operations against perceived threats.
🌐 International: Because it raises concerns about cybersecurity and information warfare globally.

📚 Background

Iranian hackers are actively targeting experts to gather intelligence on security and political perspectives.

📝 Key Evidence

"A subgroup of a hacking group called 'Mint Sandstorm' has been targeting these experts since November."
→ This proves the active cyber operations linked to Iran.
📡 Source: STATE MEDIA
📊 Confidence: 80%
VOA Persian is a state-affiliated media outlet with a focus on Iranian affairs.

Microsoft has announced in a new report that prominent regional experts in the Middle East from universities and research institutions in the United States, the United Kingdom, Belgium, France, Israel, and even Gaza have been targeted by hackers believed to be linked to the Islamic Republic and centers in Tehran. According to the Israeli newspaper 'Jerusalem Post', the report states that a subgroup of a hacking group called 'Mint Sandstorm' has been targeting these experts since November using a phishing scheme. Phishing involves sending deceptive links or forms to individuals to trick them into revealing personal information such as passwords and credit card numbers online. Accordingly, the 'Mint Sandstorm' campaign has also used 'custom phishing bait' to lure targets into 'downloading malicious files'. In a few cases, Microsoft has observed new post-intrusion behavior, including the use of a new 'custom backdoor' called 'MediaPl'. The report adds that journalists, researchers, university professors, or others who have 'insight or perspectives on security and political issues of interest to Tehran', as well as individuals who collaborate with intelligence and policy-making communities or have the potential to influence them, are considered 'attractive targets' for hackers seeking to gather information for governments like the Islamic Republic. Given the identity of some observed targets in this phishing campaign and the use of 'baits related to the Israel-Hamas war', it is likely that this process is an attempt to gather 'views related to events associated with the war' from individuals across various ideological spectrums involved in it. On the other hand, entities associated with the Islamic Republic and the Islamic Revolutionary Guard Corps have previously targeted groups they deemed hostile, including Israeli individuals and organizations. In this context, a cyberattack in November led by Tehran and the terrorist group Hezbollah targeted the Ziv Medical Center in Safed (northern Israel) and succeeded in infiltrating 'hospital information systems' and accessing sensitive personal information of patients. In September, a cyberattack from Iran sent 'fake messages' to users of a 'job search website in Israel'. The hackers pretended that the messages were official from job websites, sending phishing messages containing 'malicious links'. Amir Rashidi: Islamic Republic hackers have advanced but lack precise tools. The United Nations: Hackers and criminals from North Korea collaborate with Asian money laundering networks. Following the attack by Islamic Republic hackers on the Pittsburgh regional water authority, U.S. states are paying attention to cybersecurity. Warning from the Israeli National Cyber Directorate: Beware of 'update' emails from Islamic Republic hackers. Microsoft: Hackers linked to the Islamic Republic have attacked defense companies with 'new malware'. Islamic Republic-affiliated hackers targeted African telecommunications companies.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →