IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Iran uses AI to speed cyber & influence operations

Iran uses AI to speed cyber & influence operations

Mon, 20th Jul 2026 (Yesterday)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Recorded Future's Insikt Group has published research on Iran's use of artificial intelligence in hybrid warfare and cyber operations, finding that the technology is increasing the speed and scale of existing activity.

The research says Iranian state-backed and state-aligned actors are using generative AI across cyber operations, information campaigns, military activity, proxy attacks and domestic control. It argues that the technology is helping Tehran withstand military, economic and political pressure by improving productivity in tasks already central to its operating model.

According to the analysis, the main cyber risks for organisations and governments include AI-assisted phishing, cyber intrusions targeting operational technology and influence operations. It also warns of the need to prepare for cyber incidents that coincide with physical disruption.

The study links some of Iran's progress to closer ties with Russia and China. Russian experience in Ukraine has helped advance AI-related military tactics and unmanned systems, while Chinese work in surveillance, data analysis and AI-enabled social control offers a model for Iran's domestic security system.

Cyber methods

The report says AI is being used to improve reconnaissance, code and malware development, translation and social engineering. In practical terms, it suggests large language models are making it easier for Iranian operators to produce convincing phishing material in foreign languages and tailor lures around current events.

It also highlights risks to Industrial Control Systems. The analysis says AI can shorten the early research stage of attacks on these environments by helping threat actors identify exposed systems and understand the technologies in use more quickly.

An analyst at Recorded Future's Insikt Group said the recent conflict had probably increased the use of generative AI by Iranian threat actors.

"The 2026 crisis likely prompted Iranian state-sponsored and state-aligned threat actors to leverage generative AI to gain productivity and tradecraft improvements across reconnaissance, code/malware development, social engineering, and translation. However, AI has not fundamentally shifted Iranian cyber capability; it is scaling and accelerating what Iranian actors were already doing. AI is accelerating the research phase during Industrial Control Systems (ICS) attacks and enabling threat actors to not only identify vulnerable systems, but also understand the unique properties of the specific technologies they are targeting. An adversary can move from intent to a list of accessible ICS targets with known default credentials in under five minutes. Iranian state-sponsored hacking groups continue to use AI to enhance their social engineering and phishing lures. The use of LLMs has likely strengthened Iran's ability to create highly convincing content through foreign-language translation, enabling greater fluency and increasingly rapid generation of conflict-themed phishing that exploits current events," the Analyst said.

Attribution challenge

The research also says AI agents may make attribution harder for investigators and defenders. By automating more of the cyber operation lifecycle, Iranian intrusion and espionage groups could make their behaviour look less distinctive and weaken methods that rely on established tactics, techniques and procedures.

The report adds that this could also support deniability, because generative AI can be used to produce personas, narratives and other material at scale. In influence campaigns, that may complicate efforts to determine whether state actors are behind online activity.

The same analyst also addressed the attribution problem.

"Automaton of key elements of a cyber operation lifecycle can obscure the patterns and operational behaviours that are used to establish a link to know threat actors. Generative AI could help facilitate deniability by enabling the scalable creation of personas, narratives and supporting content that can obscure state involvement," the Analyst said.

The findings present Iran's use of AI as an expansion of established methods rather than a sudden shift in technical sophistication. That distinction matters for defenders because it suggests the immediate threat lies in greater operational tempo, lower effort per campaign and more convincing execution across familiar attack types.

For critical infrastructure operators, the emphasis on operational technology and Industrial Control Systems points to risks beyond data theft or corporate espionage. Intrusions into those environments can affect physical processes, which is why the report calls for resilience against combined cyber and physical disruption.

Recorded Future says it serves more than 1,900 businesses and government organisations across 80 countries. Insikt Group based the analysis on cybersecurity and AI threat reporting, social media activity, Iranian state messaging, government and military communications, and activist investigations.

"AI has become an important force multiplier across the cyber and information domains, enabling Iranian state-backed actors to generate cyber effects faster, identify vulnerabilities more effectively, and scale influence campaigns more efficiently. As tensions with its adversaries remain heightened, Iran's digital capabilities will likely remain active and a threat environment," the Analyst said.