ACTIVE CAMPAIGN
Iranian operations escalating · Q2 2026
HiveForce Labs · Threat Intelligence

Frontline intelligence on

nation-state cyber threats.

Gated threat reports and active advisories from HiveForce Labs. Tracking the state-sponsored operations targeting your industry, your geography, and your infrastructure.

01 · RECON
Reconnaissance
External surface mapped
02 · ACCESS
Initial Access
CVE / phish / valid creds
03 · PERSIST
Persistence
Footholds & backdoors
04 · LATERAL
Lateral Movement
Cloud & identity pivot
05 · IMPACT
Impact
Exfil / disruption
5
Actors Tracked
270+
Threat Groups
60
Pages Published

Why This Matters

Nation-state attacks aren't theoretical.

They're 

targeting you now.

Geopolitical conflict has moved into the network layer. Iranian, Russian, Chinese, and North Korean operations are actively probing Western enterprises, with TTPs that bypass traditional vulnerability management. This hub is where HiveForce Labs publishes what we're seeing in the field.

01

Gated, in-depth threat reports for each nation-state actor we actively track.

02

Open threat advisories on specific CVEs, exploits, and campaigns tied to state-sponsored groups.

03

Briefing-list signup for nation-state coverage we're actively researching.

Iran · ACTIVE COVERAGE

IR

ACTIVE COVERAGE

Iran

Iranian state-sponsored groups have escalated operations against Western infrastructure following the regional conflict. HiveForce Labs is actively tracking multiple campaigns targeting energy, financial services, government, and critical infrastructure.

Iran · Threat Reports

Iran · Recent Threat Advisories

UAE · COMING SOON

UAE

COMING SOON

UAE

Coverage of cyber threats targeting organizations across the UAE, including attacks against government, financial services, energy, technology, and critical infrastructure sectors. Report in development.

UAE · Recent Threat Advisories

TA2025183

Zero-Day Stealth: Inside Stealth Falcon’s Abuse of CVE-2025-33053

Stealth Falcon, a long-active cyber-espionage group, exploited a zero-day vulnerability in Windows (CVE-2025-33053) to target a Turkish defense firm using a malicious file disguised as a PDF.

Other Actors · COMING SOON

?

COMING SOON

Other Actors

Coverage of unattributed state-sponsored activity and criminal groups with suspected state affiliations. Includes ransomware operators with state-tolerated operations and hybrid criminal/state actors.

Other Actors · Threat Reports

TA2026084

TeamPCP's Automated Supply Chain: From Trivy to LiteLLM in a Multi-Ecosystem Breach

Stealth Falcon, a long-active cyber-espionage group, exploited a zero-day vulnerability in Windows (CVE-2025-33053) to target a Turkish defense firm using a malicious file disguised as a PDF.

Other Actors · Recent Threat Advisories

Talk to Hive Pro

Book a Demo →

Looking for general threat research and resources?

Reduce real exposure. Not just vulnerability volume.