RadioCSIRT - Edition Française · Marc Frédéric GOMEZ

Ep.597 - RadioCSIRT - Épisode Spécial : La guerre cyber au Moyen-Orient – samedi 14 mars 2026

·41 min·3 clips
Marc-Frédéric Gomez reveals how a 15-day cyber war in the Middle East permanently reshaped global cybersecurity.
1. RadioCSIRT episode 597, hosted by Marc-Frédéric Gomez on March 14, 2026, covers 15 days of cyber operations accompanying the US-Israel military strikes against Iran. 2. Gomez identifies himself as the sole host, presenting this as a special analytical episode distinct from the daily news format, drawing on sources including Symantec, Checkpoint, Flashpoint, NCC Group, Unit 42, Intel 471, and Netblock. 3. The episode's thesis is that the cyber dimension of the US-Israel-Iran conflict constitutes 'perhaps the most significant case study in cyber integration into modern military operations since Stuxnet.' 4. In October 2025, Muddy Water targeted over 100 government entities in the Middle East and North Africa via spear phishing; in December 2025, ESET published a backdoor called Muddy Viper targeting Israeli and Egyptian critical infrastructure. 5. By early February 2026, three weeks before the strikes, Muddy Water had pre-positioned backdoors named DINDOOR and FEC7 in US and Israeli networks, confirmed by Symantec and Broadcom. 6. On February 28, the US Cyber Command was designated 'First Mover,' with cyber operations beginning before the first missile; within 48 hours, over 1,250 targets were struck and Iranian internet connectivity fell to 1-4%. 7. Israel exploited multi-year access to Tehran traffic cameras to assist targeting, hacked the Bard Sabah prayer app with 5 million downloads to send defection messages to Iranian military, and redirected the IRNA news agency website, all confirmed by the Financial Times and NPR. 8. The 313 Team struck 26 Kuwaiti government domains simultaneously on March 6, covering defense, health, and civilian infrastructure, with Intel 471 confirming Kuwait as the second most impacted territory after Israel. 9. On March 6, Symantec published confirmation that Muddy Water's DINDOOR and FX8 implants had been in place since early February inside a US bank, an airport, and an Israeli subsidiary of an aerospace and defense software vendor. 10. On March 9, the CSIS published a report concluding that cyber is now a distinct conflict domain rather than a complement to physical strikes; the FBI and NSA issued a joint advisory to US defense contractors on the immediate Iranian threat. 11. On March 12, Andala claimed a wiper attack against Striker, a US medical device manufacturer, via a Microsoft vector; Striker confirmed a global Microsoft environment disruption but detected no known malware. 12. Cotton Sandstorm, also known as Emenet Pazar or PasaGard, reactivated a dormant persona called the Altoufan Team in March 2026 to target Bahrain, deploying the Wezrat stealer via spear phishing disguised as a software update. 13. Flashpoint confirmed that the pro-Russian group Noname057-16 joined the pro-Iranian coalition on March 2 under Operation Israel, targeting Israeli political parties, telecom operators, and water systems. 14. Checkpoint confirmed on March 11 that Andala had been routing operations through Starlink IP ranges since January 2026, allowing it to bypass geographic blocking. 15. GPS spoofing affected over 1,100 vessels in the Persian Gulf covering Iranian, Emirati, Qatari, and Omani waters, disrupting maritime traffic in one of the world's most critical energy transport corridors. 16. Gomez notes that the FAD Team claimed a global SQL injection campaign targeting a US Air Force virtual group and educational institutions in France, India, and Vietnam, though French institutions have not confirmed being targeted. 17. The episode's tone is analytical and source-critical: Gomez explicitly flags each unverified claim and assigns a confidence level, distinguishing confirmed multi-source reports from single-source hacktivist announcements. 18. Gomez delivers the episode as a structured solo analysis, moving through pre-conflict context, a day-by-day chronology, actor portraits, MITRE ATT&CK-mapped techniques, and defensive recommendations. 19. Security professionals, incident response teams, and CTI analysts tracking Iranian APT and pro-Russian hacktivist activity will find the actor-by-actor breakdown and MITRE references directly actionable. 20. Listeners who prefer general news summaries or who need English-language content will not find this episode useful.
Listen to the show on