Key takeaways
- Iran's most effective tactic is patience: weeks of harmless, friendly messages before a single malicious link appears.
- The targets aren't voting machines. They're the people who run, litigate, report on and coordinate elections.
- Iranian operators increasingly use a target's own admin tools, which leaves no malware signature to catch.
- The goal isn't to pick a winner. It's to make a big share of Americans doubt the result, whoever wins.
Part 2 of an extended conversation with the machine about threats to the '26 midterms.
Part 1 laid out the structural picture: the administration dismantled federal election cybersecurity while using the threat of Iranian interference as political cover. Part 2 is the operational layer: how Iranian cyber actors actually work, and what that means for 2026.
This matters for anyone trying to judge what foreign interference would actually look like, as opposed to what the administration says it looks like.
Who controls what
Iran's cyber operations run through two intelligence structures. The Islamic Revolutionary Guard Corps runs the most aggressive work: election interference, influence campaigns and destructive attacks. Its intelligence arm controls APT42, the group most directly tied to targeting U.S. elections. The Ministry of Intelligence and Security runs longer-term espionage, persistent access and large-scale data collection through groups like APT34 and MuddyWater.
Six tactics
1. Patient social engineering, their signature move
APT42 makes contact posing as a journalist, think tank researcher or conference organizer. The first email has nothing malicious in it. The goal is just a reply. By the time a malicious link shows up, the target has traded several friendly messages with what looks like a credible professional. The group has impersonated real, named journalists at the Brookings Institution and the Institute for the Study of War. After building rapport, they move targets to Signal, Telegram or WhatsApp, where people let their guard down.
In 2026, the likely targets are campaign staff, state election officials, secretaries of state, election security researchers, journalists who cover election integrity and voting rights lawyers.
2. Credential phishing at scale
Once contact is established, the goal is login credentials for email, cloud storage and messaging. Inside an account, operators immediately add backup access, such as a new recovery email or an app password, so changing the password doesn't lock them out. Their phishing pages have posed as The Washington Post, The Economist and various NGOs. In 2024, APT42 got into personal email accounts tied to both the Biden and Trump campaigns.
Compromising a secretary of state's personal Gmail account yields influence without touching a single vote-counting system.
3. Fake news sites aimed at both sides
Iran runs fake outlets aimed at left-leaning and right-leaning audiences at the same time. The goal isn't to favor one side. It's to maximize division and erode trust. In 2024, OpenAI caught Iranian-linked accounts using ChatGPT to write political content designed to pass as American discourse. With the country already split over the Iran war, it takes very little fabrication to amplify rage on either side. The question is whether anyone is still positioned to catch it.
4. Living off the land
Since about 2023, Iranian operators have shifted from custom malware to the target's own tools: PowerShell, standard IT software and cloud services like Google Drive and OneDrive. When an attacker uses your own tools, there's no new signature for antivirus to catch. A state election board that has never been hit with Iranian malware may still have been entered by Iranian operators using the board's own admin tools.
5. Destructive wipers
When Iran shifts from spying to retaliation, it uses wipers, malware built to permanently destroy data. Current versions overwrite files so recovery is impossible, backups or not. Since Operation Epic Fury began Feb. 28, 2026, destructive attacks have already hit cloud data centers in the UAE and Bahrain. A wiper attack on voter registration systems in a contested state weeks before an election would be catastrophic, whether Tehran ordered it or an allied group acted alone.
6. Population-scale data collection
Several Iranian groups target ISPs, medical systems and telecom providers for huge personal data sets. In the election context, voter rolls, ISP records and telecom data are the raw material for precision influence campaigns aimed at specific voters in specific precincts.
What interference in '26 would actually look like
The popular image of hackers changing vote totals is almost certainly wrong. Iranian operations have never aimed at vote counts. They aim at something easier and longer-lasting: trust in the process.
- Already underway: harvesting credentials from campaign staff, election lawyers, secretaries of state and journalists.
- Before the election: synthetic news and social amplification on both left and right, using the Iran war as a ready-made wedge.
- October: selective leaks of real, stolen material, timed before early voting.
- Election week: a possible disruptive attack on registration or results reporting in contested states, not to change outcomes but to create confusion.
The goal isn't to install a preferred candidate. It's to make sure that whoever wins, a big share of the public doubts the result.
Why this cycle is different
The federal detection layer is gone: the EI-ISAC's real-time threat sharing across states, CISA's election security team and its liaison work with allied intelligence services. What remains are academic labs without classified intelligence, state election offices with uneven capacity, slimmed-down platform trust and safety teams, and FBI field offices without central coordination.
That's not nothing. But it's far less than in 2020 or 2024, and the attackers know it.
Sources
- Trellix: The Iranian Cyber Capability 2026
- Palo Alto Unit 42: Iranian Cyber Threat Evolution
- Picus Security: Iranian Threat Actors — What Defenders Need to Know
- Ekco: Iran Cyber Attacks 2026
- Halcyon: Iranian Use of Cybercriminal Tactics in Destructive Attacks
- Security Scientist: How to Defend Against Iranian APT Groups
- Brandefense: APT35 — Iran's Persistent Cyber Espionage Force
- Google Mandiant: Untangling Iran's APT42 Operations
- The Record: Iranian hackers targeting affiliates of both U.S. presidential campaigns
- The Hacker News: OpenAI Blocks Iranian Influence Operation
- GovInfoSecurity: Iran Amplifies US Election Influence Campaign
- Washington Times: Meet the Iranian cyberattackers suspected of trying to hack the U.S. election
- FINRA: Heightened Threats From Iranian Cyber Actors
- Palo Alto Unit 42: Escalation of Cyber Risk Related to Iran
Originally published on LinkedIn, April 26, 2026. Lightly edited.