LevelBlue Acquires Fortra’s Alert Logic MDR Business, Strengthening Position as Global MDR Leader. Learn More

LevelBlue Acquires Fortra’s Alert Logic MDR Business, Strengthening Position as Global MDR Leader. Learn More

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Infrastructure Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft Security
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
PGA of America Partnership
Secure What's Next
LevelBlue Security Operations Platforms
Security Colony
Partners
Microsoft
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings

45 Minute Watch Ziv Mador,
VP Security Research

As Operation Epic Fury unfolds, the battlefield has extended well beyond kinetic strikes. Iran’s near-total Internet blackout is only the most visible layer of a much broader hybrid conflict. Beneath the disruption, a coordinated activation of Iranian-state sponsored cyber operators is underway.

This is not a single destructive event; it is a structured escalation model, blending espionage, access development, disruption, and influence operations.

In this 45-minute threat intelligence briefing, Ziv Mador, VP Security Research, breaks down what LevelBlue SpiderLabs has observed, how we have elevated monitoring for clients in recent days, and what detection and response priorities security leaders should implement now. In this session, you’ll learn:

  • How Iranian threat actors MuddyWater, Charming Kitten, OilRig, APT33, and affiliated operators are evolving their tradecraft 
  • The core TTPs driving escalation: credential theft, cloud abuse, supply chain compromise, custom malware, wiper staging, and OT targeting
  • Early retaliation signals, from reconnaissance and DDoS to destructive pre-positioning
  • How to align SOC detection with the intrusion-to-disruption lifecycle
  • Which critical infrastructure sectors are most at risk and why.

Watch the Webinar

Related Resources

Current: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Resource: resourceswebinarsttp-briefing-in-focus-latest-threats-and-trends-from-the-frontlines
Webinar

TTP Briefing in Focus: Latest Threats and Trends from the Frontlines

Current: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Resource: resourceswebinarslockbit-5.0-faster-quieter-harder-to-stop
Webinar

LockBit 5.0: Faster, Quieter, Harder to Stop

Current: resourceswebinarsepic-fury-decoded-irans-cyber-escalation-playbook
Resource: resourceswebinarsbec-unmasked-how-ai-driven-dual-channel-attacks-are-evolving-in-2026
Webinar

BEC Unmasked: How AI-Driven, Dual-Channel Attacks Are Evolving in 2026