State-Sponsored Cyber Attacks Target North American Infrastructure Amid Rising Geopolitical Tensions
Recent state-sponsored cyber operations have intensified against North American critical infrastructure, with actors from Russia, Iran, and China leveraging advanced tactics to exploit vulnerabilities.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- Cybercriminal
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, North America has witnessed a significant escalation in state-sponsored cyber attacks targeting critical infrastructure sectors, including energy, telecommunications, and defense. Adversaries from Russia, Iran, and China have employed sophisticated tactics, often integrating artificial intelligence (AI) to enhance the scale and precision of their operations.
Russian Cyber Operations
In March 2026, Russian state-sponsored group Forest Blizzard (APT28) initiated a large-scale cyber-espionage campaign targeting TP-Link home and small office routers. By exploiting weak password protections and unpatched vulnerabilities, the group compromised over 5,000 devices across more than 200 organizations. This operation enabled the hijacking of DNS traffic, facilitating Adversary-in-the-Middle (AitM) attacks that intercepted login credentials and sensitive communications. The affected sectors included government, energy, IT, and telecommunications, with the potential for more severe attacks due to the broad access gained. (techradar.com)
Iranian Cyber Activities
Following the U.S. and Israeli military strikes against Iran in February 2026, Iranian-affiliated threat actors have escalated cyber operations targeting American critical infrastructure. U.S. agencies, including the FBI, CISA, and NSA, issued a joint advisory warning of ongoing attacks exploiting internet-connected operational technology devices, such as Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). These intrusions have led to operational disruptions, manipulation of system interfaces, and financial losses in sectors like government services, water and wastewater systems, and energy. The attacks are believed to be retaliatory, with the group linked to Iran’s Islamic Revolutionary Guard Corps (IRGC), known previously as CyberAv3ngers or Shahid Kaveh Group. (techradar.com)
Chinese Cyber Operations
Chinese state-sponsored groups have also been active, with reports indicating the use of AI agents to autonomously execute cyberattacks. In late 2025, a Chinese state-sponsored group utilized AI agents to conduct cyberattacks on approximately 30 targets, with the AI handling 80–90% of operational tasks independently. This development underscores the growing integration of AI in cyber operations, enhancing the efficiency and scale of attacks. (axios.com)
U.S. Military Cyber Response
In response to the escalating cyber threats, the U.S. has bolstered its cyber defense capabilities. The U.S. Army Cyber Protection Brigade, known as the "Hunter Brigade," is a key component in safeguarding critical infrastructure. Established in 2015 and headquartered at Fort Gordon, Georgia, the brigade conducts defensive cyber operations, including "hunt forward operations" to identify and mitigate cyber threats before they impact networks. (en.wikipedia.org)
Recommendations for Mitigation
Organizations are advised to implement the following measures to enhance resilience against state-sponsored cyber threats:
-
Regular Vulnerability Assessments: Conduct comprehensive evaluations to identify and remediate system weaknesses.
-
AI Integration in Defense: Leverage AI-driven security solutions to detect and respond to threats more effectively.
-
Employee Training: Educate staff on recognizing phishing attempts and other social engineering tactics.
-
Incident Response Planning: Develop and regularly update incident response protocols to ensure swift recovery from cyber incidents.
The evolving cyber threat landscape necessitates a proactive and adaptive approach to cybersecurity, particularly in the face of increasingly sophisticated state-sponsored operations.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

China-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure

China-Aligned APTs Pivot to AI and Robotics Espionage in South Korea and Gulf States

