Operation Epic Fury: Iran's Cyber Proxy War and the Risk to Europe
On February 28, 2026, Operation Epic Fury triggered a global cyber cascade. Sixty Iranian proxy groups already pre-positioned in cloud environments, SCADA systems, and European supplier networks launched coordinated operations. In 72 hours: 149 DDoS attacks against 110 organizations in 16 countries, 60+ groups mobilized, 20% of global LNG supply disrupted, and the Handala wiper reaching 79 countries.
The Geopolitical Context: Three Decades of Iranian Cyber Doctrine
On February 28, 2026, American and Israeli missiles and fighter-bombers struck Iranian military installations, eliminating Supreme Leader Khamenei and decapitating the leadership of the Islamic Revolutionary Guard Corps (IRGC). Simultaneously, Israel conducted the largest offensive cyber operation in history, collapsing Iranian internet connectivity to 1-4% of normal traffic — as confirmed by NetBlocks.
Iran's response has roots dating back to 2010. Stuxnet taught Tehran that cyberwar can destroy isolated physical systems. Since then, Iran has built a hybrid ecosystem of state APTs and hacktivist collectives operating as deniable proxies. The ecosystem is structured around IRGC-CEC and MOIS, with APT33 (aerospace/energy), APT34/OilRig (Oil & Gas), APT35/APT42 (AI-assisted spear-phishing), MuddyWater (initial access broker), and Handala (hack-and-leak).
The Trilateral Pact Iran-China-Russia: a New Cyber Axis?
On January 29, 2026 — one month before kinetic operations — Iran, China, and Russia signed a trilateral strategic pact in Tehran. On the cyber front, the pact consolidates already existing cooperation: China provided satellite imagery and early warning data, Russia agreed to rebuild air defense systems. The cooperation includes sharing of anonymization infrastructure, exchange of zero-day vulnerabilities, and offensive tooling — as analyzed by Small Wars Journal and CSIS.
Anatomy of the Offensive: TTPs, Timeline, and Attack Chains
In the first 72 hours, a coalition of over 12 groups executed 149 DDoS attacks against 110 organizations in 16 countries. The number of mobilized groups rose to 60+, including pro-Russian formations such as NoName057(16) which on March 3 joined the pro-Iranian coalition — confirmed by Tenable RSO, Palo Alto Unit 42, Flashpoint, and Recorded Future.
The real threat was already in position before kinetic operations began. Tenable's analysis revealed that MuddyWater had infiltrated Israeli and MENA networks in the preceding weeks with silent backdoors. On the day of the military operation, that access was weaponized. This 'weaponization of pre-positioned access' is Iran's most advanced operational paradigm.
The most documented case is the Handala attack against Stryker Corporation on March 11, 2026. In three hours, Handala wiped Stryker's endpoints across 79 countries on six continents. Stryker manufactures orthopedic implants — no role in the conflict, no operations in the Middle East. Access was likely obtained via Microsoft Intune or a supply chain vector. Production lines halted. Hospitals waiting for surgical devices received silence.
The European Risk: We Are Not Observers
Europe is an attack surface, not a spectator. NoName057(16) conducted DDoS campaigns in Romania and Denmark. DieNet claimed 100 attacks in a single day. The Handala operation reached organizations in 16 European countries through the supply chain. Finland, in its National Security Overview 2026, explicitly flagged Iran as a risk vector alongside Russia and China.
For Italy, the risk is specific: NATO bases (Aviano, Sigonella, Naples) as symbolic targets, the port of Gioia Tauro as a port disruption target, the energy sector exposed to the closure of the Strait of Hormuz and the disruption of 20% of global LNG supply. Every Italian organization with branches, suppliers, or digital partners in the Gulf area must consider itself in scope.
The question to ask is not 'have we been attacked?' but 'have we already been compromised without knowing it?'. APT33 targets the European aerospace and Oil & Gas sector. APT34/OilRig strikes European companies to gain access to industrial controllers. MuddyWater targets telecommunications and IT vendors as a springboard toward higher-value targets.
The ICS/OT Paradigm: When Cyberwar Strikes the Physical World
CyberAv3ngers and Charming Kitten are actively searching for internet-exposed PLCs and accessible HMIs — control panels for water systems, power plants, and waste treatment facilities. Among claimed operations: access to an HMI system of a US water treatment plant with screenshots of chlorine levels, penetration of grain silos in Jordan, access to Israeli water pumps with remote control of valves.
Tenable's analysis identified over 15.5 million vulnerable assets across the seven target countries. A single vulnerability — CVE-2026-21514, an OLE bypass in Microsoft Word — accounts for nearly 14 million of those targets. Added to the CISA KEV catalog on February 10, 2026, Russian APT28 had already exploited it in January 2026 against targets in Ukraine, Slovakia, and Romania — a possible exploit-sharing between the Russian-Iranian network.
Why Post-Quantum Is Relevant Today, Not Tomorrow
The proliferation of actors with pre-positioned access introduces the 'harvest now, decrypt later' problem. Iranian groups, with Chinese and Russian technical support, are collecting intercepted encrypted traffic to retroactively decrypt it with future quantum computers. For European organizations handling sensitive information — defense, energy, pharmaceuticals — current cryptography (RSA, ECC) does not guarantee confidentiality even for data already transmitted.
The Stryker case demonstrated that the execution speed of a destructive operation — three hours for 79 countries — dramatically exceeds the response speed of traditional SOC teams. A Zero Trust model with micro-segmentation, continuous authentication, and NIST post-quantum cryptography (ML-KEM for key encapsulation, ML-DSA for digital signatures) reduces the lateral movement surface. This is not a marketing argument: it is the difference between a contained incident and a global wipe.
Operational Recommendations
- 1.Urgent patching of CVE-2026-21514 and all CVEs in the CISA KEV catalog associated with Iranian actors
- 2.Audit of all remote access paths to OT/ICS systems, with attention to exposed PLCs and HMIs
- 3.Review of the digital supply chain — vendors, MSPs, cloud partners — with threat modeling for pre-positioned access
- 4.Implementation of wiper detection and rapid endpoint isolation response
- 5.Enhancement of DDoS mitigation capabilities, with resilience verification on DNS and BGP
The NIS2 framework, in force for all European essential service operators, imposes exactly these requirements as a minimum, not a maximum. Operation Epic Fury is not an event confined to the Middle East: it is a catalyst that activated a pre-existing global network designed to operate autonomously.
The current geopolitical landscape, with the convergence of Iranian capabilities, Chinese support, and pro-Russian coordination, represents exactly the scenario for which migration to post-quantum cryptography and Zero Trust is not a three-year roadmap: it is an immediate operational priority.