149 Hacktivist DDoS Claims Strike 110 Organizations in 16 Countries Following Middle East Military Operations
Security teams are warning of a sharp uptick in politically motivated cyber disruptions after a joint U.S.-Israel military campaign, tracked under the codenames Epic Fury and Roaring Lion. In a Tuesday report, Radware highlighted that much of the recent hacktivist activity is concentrated in a few actors and spiked in the days immediately following the operations.
Radware noted that two collectives, Keymous+ and DieNet, were responsible for almost 70% of attack activity observed between February 28 and March 2. The initial distributed denial-of-service incident tied to the wave was attributed to Hider Nex (also known as Tunisian Maskers Cyber Force), which began operations on February 28, 2026.
Orange Cyberdefense has profiled Hider Nex as a shadowy Tunisian hacktivist cell aligned with pro-Palestinian causes. The group reportedly uses a combined tactic of DDoS assaults and data theft followed by public disclosures-so-called hack-and-leak operations-to advance its political messaging. Hider Nex first appeared on the threat landscape in mid-2025.
Across the campaign window, investigators logged 149 separate hacktivist DDoS claims that targeted 110 unique organizations in 16 countries. Twelve distinct groups claimed responsibility for the incidents; Keymous+, DieNet and NoName057(16) together made up about 74.6% of the total activity, according to aggregated telemetry.
The Middle East bore the brunt of the activity, with 107 of the attacks occurring there and a heavy focus on state and public-facing infrastructure. Europe accounted for roughly 22.8% of activity during the same interval. When measured by sector, almost 47.8% of targeted entities were government bodies, followed by finance at 11.9% and telecommunications at 6.7%. Radware pointed out that this digital campaign has expanded alongside kinetic operations, and that three countries saw the lion’s share of claims inside the region: Kuwait (about 28%), Israel (27.1%), and Jordan (21.5%).
Additional disruptive actors observed by intelligence firms including Flashpoint and Palo Alto Networks’ Unit 42, and cited by Radware, include Nation of Saviors (NOS), Conquerors Electronic Army (CEA), Sylhet Gang, 313 Team, Handala Hack, APT Iran, Cyber Islamic Resistance, Dark Storm Team, the FAD Team, Evil Markhors, and PalachPro.
Beyond mass DDoS claims, several other notable cyber operations have been reported. Pro-Russian hacktivist collectives such as Cardinal and Russian Legion claimed breaches of Israeli military systems, alleging access to components of the Iron Dome air-defense network.
CloudSEK uncovered an SMS phishing campaign distributing a fake version of Israel’s Home Front Command RedAlert mobile app. The attackers trick victims into sideloading a malicious APK presented as an urgent wartime update; the counterfeit app provides an authentic alert interface while covertly installing surveillance and data-exfiltration functionality.
Flashpoint reported Iran’s Islamic Revolutionary Guard Corps (IRGC) has directed operations at regional energy and digital infrastructure, citing attacks on Saudi Aramco and an Amazon Web Services data center in the U.A.E. that it characterized as intended to maximize global economic pressure in retaliation for military setbacks.
Operators tied to Cotton Sandstorm (also called Haywire Kitten) resurfaced under an older alias, Altoufan Team, and claimed defacements of Bahraini websites-an activity Check Point interprets as a reactive pattern that could presage more intrusions across the region as the conflict continues.
Nozomi Networks’ telemetry shows that the Iranian state-linked group tracked as UNC1549 (aliases GalaxyGato, Nimbus Manticore, Subtle Snail) ranked as the fourth most active actor in the latter half of 2025, concentrating on defense, aerospace, telecom and regional government targets to further Tehran’s strategic aims.
Iranian cryptocurrency platforms have remained operational but many have altered procedures-pausing or batching withdrawals and issuing advisories-citing increased risk of connectivity disruption. Ari Redbord, TRM Labs’ global head of policy, said the markets are not showing clear signs of mass capital flight; rather, crypto infrastructure in Iran is being stress-tested by war, intermittent connectivity and tighter regulatory controls.
Sophos reported a rise in hacktivist actions-primarily from pro-Iran personas including the Handala Hack team and APT Iran-in the form of DDoS campaigns, website defacements and unverified breach claims, but described the increased activity as a surge rather than a change in overall risk profile.
The U.K. National Cyber Security Centre has warned organizations to expect a heightened threat from Iranian cyber operations and urged defenders to strengthen controls against DDoS, phishing and attacks targeting industrial control systems.
Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center and a former FBI Cyber Division deputy assistant director, wrote on LinkedIn that Iran has a history of tolerating or leveraging private cyber actors to retaliate for perceived political grievances, and that ransomware has become a more prominent tool in such reprisals. Kaiser suggested Tehran may permit or direct these groups if their activity can deliver useful retaliatory effects.
SentinelOne has assessed with high confidence that entities in Israel, the United States and allied nations are likely to be targeted-directly or indirectly-especially within government, critical infrastructure, defense, financial services, academia and media sectors.
Nozomi Networks emphasized that Iranian threat actors often combine espionage, disruptive operations and influence campaigns to pursue strategic objectives; during unstable periods they tend to escalate attacks against critical infrastructure, energy systems, government institutions and private industry well beyond the immediate theaters of conflict.
To mitigate the heightened cyber risk, security practitioners are advised to enable continuous monitoring to capture elevated activity, refresh threat intelligence signatures, shrink externally exposed attack surfaces, perform thorough exposure reviews of internet-connected assets, verify segmentation between IT and OT environments, and isolate IoT devices.