{"id":323661,"date":"2026-03-05T19:27:16","date_gmt":"2026-03-05T19:27:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/323661\/"},"modified":"2026-03-05T19:27:16","modified_gmt":"2026-03-05T19:27:16","slug":"interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/323661\/","title":{"rendered":"Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East"},"content":{"rendered":"<p>Key Findings<\/p>\n<p>During the ongoing conflict, we identified intensified targeting of IP cameras from two manufacturers starting on February 28, originating from infrastructure we attribute to Iranian threat actors.<\/p>\n<p>The targeting extends across Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus \u2013 countries that have also experienced significant missile activity linked to Iran. On March 1st, we additionally observed camera-targeting activity focused on specific areas in Lebanon.<\/p>\n<p>We also observed earlier, more targeted activity against cameras in Israel and Qatar on January 14\u201315. These dates surround with Iran\u2019s temporary closure of its airspace, reportedly amid expectations of a potential U.S. strike.<\/p>\n<p>Taken together, these findings are consistent with the assessment that Iran, as part of its doctrine, leverages camera compromise for operational support and ongoing battle damage assessment (BDA) for missile operations, potentially in some cases prior to missile launches. As a result, tracking camera-targeting activity from specific, attributed infrastructures may serve as an early indicator of potential follow-on kinetic activity.<\/p>\n<p>Introduction<\/p>\n<p class=\"wp-block-paragraph\">As highlighted in the\u00a0<a href=\"https:\/\/www.checkpoint.com\/security-report\/\" rel=\"nofollow noopener\" target=\"_blank\">Cyber Security Report 2026<\/a>, cyber operations have increasingly become an additional tool in interstate conflicts, used both to support military operations and to enable ongoing battle damage assessment (BDA). During the 12-day conflict between Israel and Iran in June 2025, the compromise of cameras was likely used to support BDA and\/or target-correction efforts.<\/p>\n<p class=\"wp-block-paragraph\">In the current Middle East conflict, Check Point Research has observed intensified targeting of cameras beginning in the first hours of hostilities, including a sharp increase in exploitation attempts against IP cameras not only in Israel but also across Gulf countries: specifically the\u00a0UAE, Qatar, Bahrain, and Kuwait,\u00a0as well as similar activity in\u00a0Lebanon\u00a0and\u00a0Cyprus. This activity originated from multiple attack infrastructures that we attribute to several Iran-nexus threat actors.<\/p>\n<p class=\"wp-block-paragraph\">Notably, we also identified earlier activity exhibiting similar patterns, dated\u00a0January 14, coinciding with the peak of anti-regime protests in Iran, a period during which Iran anticipated potential action from the United States and Israel and temporarily closed its airspace.<\/p>\n<p>Findings<\/p>\n<p class=\"wp-block-paragraph\">Check Point Research (CPR) continuously tracks infrastructure used by Iran-nexus threat actors.<\/p>\n<p class=\"wp-block-paragraph\">Starting\u00a0February 28, we observed a spike in targeting of IP cameras in several countries in the Middle East including\u00a0Israel,\u00a0UAE, Qatar, Bahrain, Kuwait and Lebanon, while also similar activity occurred against Cyprus.<\/p>\n<p class=\"wp-block-paragraph\">The attack infrastructure we track combines specific commercial VPN exit nodes (Mullvad, ProtonVPN, Surfshark, NordVPN) and virtual private servers (VPS), and is assessed to be employed by multiple Iran-nexus actors.<\/p>\n<p class=\"wp-block-paragraph\">Scanning activity we observed targets cameras such as\u00a0Hikvision\u00a0and\u00a0Dahua\u00a0and aligns with attempts to identify exposure to the vulnerabilities listed below. No attempts to interact with other camera vendors were observed from this infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">The popular devices\u00a0of Hikvision and Dahua are targeted with the following vulnerabilities:<\/p>\n<p>CVEVulnerabilityCVE-2017-7921An improper authentication vulnerability in Hikvision IP camera firmwareCVE-2021-36260A command injection vulnerability in the Hikvision web server componentCVE-2023-6895An OS command injection vulnerability in Hikvision Intercom Broadcasting SystemCVE-2025-34067An unauthenticated remote code execution vulnerability in Hikvision Integrated Security Management PlatformCVE-2021-33044An authentication bypass vulnerability in multiple Dahua products<\/p>\n<p class=\"wp-block-paragraph\">Patches are available for all of the vulnerabilities listed above.<\/p>\n<p class=\"wp-block-paragraph\">As a case study, we conducted a deep dive into two of the CVEs listed above \u2013 CVE-2021-33044 and CVE-2017-7921 \u2013 and examined exploitation attempts originating from operational infrastructure we attribute to Iran, observed since the beginning of the year.<\/p>\n<p>Waves of activity against Israel:<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" width=\"1482\" height=\"894\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image1.png\" alt=\"\" class=\"wp-image-32791\"  \/><\/p>\n<p class=\"wp-block-paragraph\">The spikes in this activity are closely aligned with geopolitical events around the same time:<\/p>\n<p>January 14-15\u00a0\u2013 While internal anti-regime protests in Iran peaked, Iranian officials and state media portrayed the unrest as a foreign-backed plot by Iran\u2019s adversaries, including the United States and Israel and also closed its airspace. At the same time we also observe a wave of scans of cameras in the Iraqi Kurdistan.<\/p>\n<p>January 24\u00a0\u2013 The U.S. Central Command (CENTCOM) commander visited Israel and met with the Israel Defense Forces\u2019 chief of staff amid heightened tensions.<\/p>\n<p>Beginning of February\u00a0\u2013 Iran\u2019s leadership was increasingly worried about a possible U.S. strike; Iranian\/IRGC-linked messaging warned a strike could trigger a wider regional war.<\/p>\n<p>Waves of activity against Qatar:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image2.png\" alt=\"\"\/><\/p>\n<p>Waves of activity against Bahrain:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image3.png\" alt=\"\"\/><\/p>\n<p>Waves of activity against Kuwait:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image4.png\" alt=\"\"\/><\/p>\n<p>Waves of activity against United Arab Emirates:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image5.png\" alt=\"\"\/><\/p>\n<p>Waves of activity against Cyprus:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image6.png\" alt=\"\"\/><\/p>\n<p>Waves of activity against Lebanon:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/XBSMBU7QWZ-image7.png\" alt=\"\"\/><\/p>\n<p class=\"wp-block-paragraph\">We observed similar targeting patterns during the 12-day war between Israel and Iran in June 2025, likely to support battle damage assessment (BDA) and\/or targeting correction. One of the best-known cases occurred when Iran struck Israel\u2019s Weizmann Institute of Science with a ballistic missile and had\u00a0<a href=\"https:\/\/www.jpost.com\/israel-news\/defense-news\/article-879689\" rel=\"nofollow noopener\" target=\"_blank\">reportedly<\/a>\u00a0taken control of a street camera facing the building just prior to the hit<\/p>\n<p>Recommendations for Defenders :<\/p>\n<p>Eliminate public exposure:\u00a0remove direct WAN access to cameras\/NVRs; place them behind VPN or a zero-trust access gateway; block inbound port-forwards.<\/p>\n<p>Enforce strong credentials:\u00a0change default passwords, enforce unique credentials.<\/p>\n<p>Patch management:\u00a0keep cameras\/NVR firmware and management software updated \u2013 updates from the manufacturers are available;\u00a0remove\/replace\u00a0end-of-life devices that no longer get security fixes.<\/p>\n<p>Network segmentation:\u00a0isolate cameras on a dedicated VLAN with no lateral access to corporate\/OT networks; tightly control outbound traffic (only to required update\/cloud endpoints).<\/p>\n<p>Monitoring &amp; detection:\u00a0repeated login failures, unexpected remote logins; cameras initiating unusual outbound connections.<\/p>\n","protected":false},"excerpt":{"rendered":"Key Findings During the ongoing conflict, we identified intensified targeting of IP cameras from two manufacturers starting on&hellip;\n","protected":false},"author":2,"featured_media":323662,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[85,46,43],"class_list":{"0":"post-323661","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-israel","8":"tag-il","9":"tag-israel","10":"tag-news"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/323661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=323661"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/323661\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/323662"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=323661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=323661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=323661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}