// 2 ZERO-DAY · 3 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing ICS reconnaissance to under five minutes, leaving AI artifacts in malware code, and scaling multi-language propaganda production.

On July 16, 2026, Recorded Future's Insikt Group published an analysis reconstructing how generative AI became a force multiplier in Iran's asymmetric warfare playbook during the conflict that began in January. Not new capabilities, but a democratization of speed: from OT reconnaissance to malware development, through influence operations at industrial scale.

Key Takeaways
  • The Iranian group CyberAv3ngers used ChatGPT for PLC reconnaissance starting in October 2024, with continued use cases in 2026
  • Google GTIG found GreenBravo/APT42 employs Gemini as an engineering platform to accelerate development of specialized malicious tools
  • The CHAR malware, identified by Group-IB in the January 26, 2026 Olalampo operation, contains emoji in debug strings — a trait rarely seen in human-authored code, indicating unsanitized AI-generated code
  • CISA advisory AA26-097A, updated July 22, 2026, confirms Iranian APTs caused operational disruption and financial losses on Rockwell Automation, Schneider Electric, and Siemens PLCs in Government Services, Water/Wastewater, and Energy sectors

From Months of Expertise to Under 5 Minutes: ICS Reconnaissance Compressed by AI

The most immediate and measurable shift concerns the reconnaissance phase on industrial systems. CloudSEK researchers, cited in the Insikt Group report, demonstrated that an actor can move from "intent" to "list of accessible US ICS devices with known default credentials in under five minutes" using an LLM agent.

This data point carries the weight of controlled proof: not a theoretical estimate, but a replication of the method already observed in operations attributed to CyberAv3ngers. The group, active since at least October 2024, continued employing commercially available tools in 2026, lowering the barrier to entry for attacks that previously required specialized OT protocol expertise.

Palo Alto Networks Unit 42 observed CL-STA-1128 activity — infrastructure associated with CyberAv3ngers — focused on Rockwell Automation/Allen-Bradley devices: 5,600 IP addresses globally detected by Cortex Xpanse. The group installed FactoryTalk software on VPS for remote PLC exploitation, confirming that AI-accelerated reconnaissance translates into concrete operational access.

Artifacts of Generated Code: When Emojis Betray the Model

The most immediate forensic evidence of AI assistance in malware development comes from the Olalampo operation, documented by Group-IB on January 26, 2026. The CHAR backdoor, written in Rust, contains emoji in its debug strings. According to Group-IB researchers, cited by Recorded Future, "the emojis indicate the operator used an AI model to generate code segments and failed to sanitize debug strings before compilation."

The trait is described as "rarely seen in human-authored code": not an intentional signature, but a compilation artifact that allows retrospective identification of the production method. The Olalampo operation deployed four malware families — CHAR, GhostFetch, GhostBackDoor, and HTTP_VIP — via spearphishing against targets in the Middle East and North Africa.

In parallel, the Google GTIG AI Threat Tracker from February 2026 documented that GreenBravo, also known as APT42, employs Gemini "as an engineering platform to accelerate the development of specialized malicious tools." The use extends to debugging, code generation, and exploitation techniques: not full automation, but compression of a development cycle that previously required weeks of specialized work.

"An actor can move from intent to a list of accessible US ICS devices with known default credentials in under five minutes"
— CloudSEK researchers, in Recorded Future/Insikt Group

Information Warfare at Industrial Scale: Multi-Language Content Production

The integration of generative LLMs has also hit the informational side of the conflict. Insikt Group finds that AI content generation enables "rapidly producing widely resonant propaganda and influence content." The mechanism does not alter the strategy — the Iranian narrative remains consistent with pre-existing doctrine — but multiplies its reach and distribution speed.

Evidence includes AI-generated images and videos, as well as networks of inauthentic social media accounts. The report does not quantify specific volumes or engagement: the actual scale of deployment remains a point to verify, as explicitly indicated in the analysis limitations. What is documented is the capacity for scalable production, not its measured impact on public opinion.

The Military Context: Quantifying the 2026 Asymmetric War

The Recorded Future report sits within a conflict characterized by massive economic and military damage. According to Carnegie Endowment data, Iran accumulated between 2,500 and 4,000 ballistic missiles and estimates up to 80,000 drones by 2026. A Shahed-136 costs between $20,000 and $50,000.

In the first week of war, Iran launched over 2,000 drones and 500 missiles. By the ceasefire, the total exceeded 1,300 missiles and 4,400 drone attacks. Damage includes 228 military facilities or equipment damaged or destroyed, a $540 million E-3 AWACS Sentry destroyed in Saudi Arabia, and economic losses to Iran estimated at $270 billion — equivalent to 57% of GDP.

CISA advisory AA26-097A, updated July 22, 2026 and signed by FBI, NSA, EPA, DOE, CNMF, and Treasury, confirms Iranian APTs caused "operational disruption and financial loss" on Rockwell Automation, Schneider Electric, and Siemens PLCs. The advisory specifies interactions with malicious project files and manipulation of HMI/SCADA displays, with IOC release in STIX format.

The advisory stresses that "the additional manufacturers being targeted emphasizes the importance for OT owners and operators to restrict direct internet access and ensure secure PLC deployment." It does not explicitly mention AI as an attack vector, but the infrastructure and TTPs described are consistent with the AI-accelerated playbook documented by Recorded Future.

Hidden Operations: Ransomware as Cover

A recurring element in the Iranian playbook — not AI-dependent but convergent with it — is the use of ransomware as a false flag for intelligence operations. According to The Record, the MuddyWater group — linked to Iran's MOIS — deployed Chaos ransomware to "obscure operational intent and complicate attribution."

Evidence included absence of actual encryption, publication of legitimate data rather than extortion, and technical indicators traceable to MuddyWater's toolkit. This obfuscation tactic, combined with the production speed offered by LLMs, creates new challenges for attribution: more automatically generated content means more noise to analyze to isolate genuine technical evidence.

What to Do Now

Sources document priority actions for defenders and OT operators:

  • Restrict direct internet access for PLCs and ensure secure controller deployment, as recommended by the joint CISA advisory AA26-097A
  • Monitor for AI artifacts in malicious code: debug strings with emoji, unsanitized generation patterns, and stylistic anomalies in Rust or C++ code
  • Analyze connections to commercial LLM services (ChatGPT, Gemini) from internal development infrastructure as a potential indicator of operation preparation
  • Assess exposure of Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens devices: the advisory confirms active targeting with escalation across multiple critical sectors

Why This Model Is Replicable

The most important reading of the Insikt Group report is not technical but strategic. Iran did not develop autonomous military AI nor surpass adversaries in algorithmic capabilities: it integrated accessible commercial tools into an asymmetric playbook proven over years. The result is a temporal compression and democratization of access that other sanctioned state actors — or non-state actors with limited resources — can replicate.

The 2026 conflict is not "the first AI war," as Carnegie Endowment contextualizes relative to prior employments in Ukraine, Israel, and Russia. It is, however, a documented case study of how generative LLM availability alters risk calculations for states that compensate structural technology gaps with speed and asymmetry. For defenses, the key indicator is no longer just the zero-day vulnerability, but reconnaissance time compressed below the detection threshold.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. recordedfuture.com
  2. carnegieendowment.org
  3. malware.news
  4. israeldefense.co.il
  5. therecord.media
  6. cisa.gov
  7. thehackernews.com
  8. unit42.paloaltonetworks.com