LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft Security
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
PGA of America Partnership
Secure What's Next
LevelBlue Security Operations Platforms
Security Colony
Partners
SentinelOne
Advancing integrated, intelligence‑driven security operations
Microsoft
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Partner Portal

45 Minute Watch Ziv Mador,
VP Security Research

As Operation Epic Fury unfolds, the battlefield has extended well beyond kinetic strikes. Iran’s near-total Internet blackout is only the most visible layer of a much broader hybrid conflict. Beneath the disruption, a coordinated activation of Iranian-state sponsored cyber operators is underway.

This is not a single destructive event; it is a structured escalation model, blending espionage, access development, disruption, and influence operations.

In this 45-minute threat intelligence briefing, Ziv Mador, VP Security Research, breaks down what LevelBlue SpiderLabs has observed, how we have elevated monitoring for clients in recent days, and what detection and response priorities security leaders should implement now. In this session, you’ll learn:

  • How Iranian threat actors MuddyWater, Charming Kitten, OilRig, APT33, and affiliated operators are evolving their tradecraft 
  • The core TTPs driving escalation: credential theft, cloud abuse, supply chain compromise, custom malware, wiper staging, and OT targeting
  • Early retaliation signals, from reconnaissance and DDoS to destructive pre-positioning
  • How to align SOC detection with the intrusion-to-disruption lifecycle
  • Which critical infrastructure sectors are most at risk and why.

Watch the Webinar

Related Resources

Current: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Resource: resourceswebinarstracing-a-multi-vector-malware-campaign-from-vbs-to-open-infrastructure
Webinar

Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure

Current: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Resource: resourceswebinarsa-cisos-guide-ai-threats-supply-chain-risk-and-security-leadership
Webinar

A CISO's Guide: AI Threats, Supply Chain Risk, and Security Leadership

Current: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Resource: resourceswebinarsttp-briefing-in-focus-latest-threats-and-trends-from-the-frontlines
Webinar

TTP Briefing in Focus: Latest Threats and Trends from the Frontlines