In the first hours after American and hit Iran on Feb. 28, while most of the world was watching missile tracks across the Middle East, something quieter was happening on the blockchain. Islamic Revolutionary Guard Corps (IRGC) operatives moved tens of millions out of their crypto wallets in the first hours, scaling to hundreds of millions in the days that followed.
RAKIA, a cyber intelligence firm that develops data analysis platforms used by governments and security agencies, had its analysts track the surge in real time, and detailed the findings as they unfolded. The funds eventually landed in wallets used by the Houthis, Hezbollah and personal safe havens for regime insiders.
It was a tell. The same regime that spent years building a $3 billion crypto operation to fund its proxies was, in the opening hours of a war, using that infrastructure to evacuate its war chest. The two months since have brought the second act: the IRGC turning that infrastructure outward, against Americans and our allies.
Irans hackers are not sophisticated. Every major Iranian operation against Americans this year has run on the same cheap fuel: stolen passwords, harvested by commodity malware, basic widely available hacking software, sold for a few dollars on dark web marketplaces America already has the tools to dismantle.
President s strikes on Feb. 28 proved this regime responds to pressure. Extending that posture into cyberspace, going after the credential supply chain the way America already goes after ransomware infrastructure, is how to shut the door on these breaches before they get any closer to home.
At the end of March, Iran-linked hackers reportedly breached FBI Director Kash Patels personal email and posted years-old photos and documents online. The pro-Iranian group Handala, which the Justice Department has formally linked to Irans Ministry of Intelligence and Security, announced that the head of Americas premier law enforcement agency was now “among the list of successfully hacked victims.”
Patel was not the only target. On March 11, the same group crippled Stryker, one of America’s largest makers, wiping more than 200,000 devices across 79 countries and disrupting care for the 150 million patients it serves a year.
On March 18, Iranian hackers defaced the website of Yeshiva World News, one of the most-read Orthodox Jewish news sites in America, replacing its homepage with images of the Iranian supreme leader. The Justice Department has documented Handala using its infrastructure to send death threats to Jewish journalists and Iranian dissidents living in America, and to solicit Mexican cartel “partners” to carry out violence on its behalf.
None of these attacks required sophisticated malware. They required one thing: a stolen password. The Stryker wipeout traces back to a single administrator credential almost certainly harvested by everyday commodity malware called an infostealer and sold for a few dollars on a Russian-language forum. The Patel breach, the Yeshiva World News defacement, the broader pattern, all of it runs on the same supply chain.
That supply chain is not in Tehran. It is in dark web marketplaces operating largely in plain sight, where infostealer operators sell millions of stolen American credentials a month to anyone with a wallet address. Iranian intelligence is one buyer in those markets. It is also a vendor, running campaigns from Iranian IP addresses against Western users to feed the same markets. Same operators. Same infrastructure. Different targets.
The escalation has not stayed in Americas lane. On May 4, the same Handala group that breached Pate
