According to Recorded Future, in a Thursday releaseresearch report, Iran-linked threat actors are leveraging artificial intelligence to enhance their cyber and information warfare capabilities, exposing the United States and its allies to a higher risk of asymmetric attacks.

These Iran-linked actors have used generative AI and large language models (LLMs) in multiple activities, including malware development, industrial control system research, and software vulnerability exploitation. There is currently no indication that Iran has developed fully autonomous AI models, but the country is clearly using AI to accelerate the deployment of its existing capabilities.

"AI has not transformed Iran into a fundamentally different cyber power, but it has compressed the distance between intent and action," Alexander Leslie, senior advisor at Recorded Future, told Cybersecurity Dive.

Industrial targets become a focus

Leslie noted that Iran-linked groups have used LLMs to map industrial control systems, research exploitation techniques, and sustain phishing conversations—even when operators are not proficient in the relevant languages. For example, the threat actor tracked as MuddyWater used AI in an operation named "Operation Olalampo." According to a February release by Group IBreport, the group used AI in January to develop four malware variants via malicious Office documents in attacks targeting organizations and individuals in the Middle East and North Africa.

Another Iran-linked group, Ababil of Minab, used ChatGPT in April in an attack against Vyncs, a U.S. GPS vehicle tracking technology company. According to Check Point Software research, the group used the technology to optimize scripts used to enumerate and drop databases in the attack. The group also claimed responsibility for anattackon the Los Angeles public transit system.

In 2024, OpenAI disclosed that CyberAv3ngers used ChatGPT for reconnaissance on programmable logic controllers (PLCs). OpenAI hasshut down multiple state-linked accounts, involving various threat activities including Iran's Charming Kitten.

External cooperation and internal limitations

Analysts believe Iran is cooperating closely with Russia and China to enhance its AI capabilities. The country faces internal constraints in independent development, partly due to damage to infrastructure.

Ari Ben Am, adjunct fellow at the Foundation for Defense of Democracies' Center on Cyber and Technology Innovation, said Iran may seek more help from China, which has been developing its own frontier AI models. "Another possibility is that they will start using Chinese models and integrate them into mainstream tools such asClaude Code, as we have already seen Chinese cyber operators do," Ben Am said.