The war with Iran is having a profound geopolitical impact. Tehran has long engaged in aggressive cyber and information warfare — but new tactics (from wildly popular AI-generated parody videos to “violence-as-a-service” recruitment models) reveal the emergence of a threat environment where state actors, extremists and criminal networks increasingly overlap.
The result is a decentralized, highly adaptive form of hybrid warfare that democratic institutions find profoundly difficult to counter.
To discuss these changes and more, ISD’s Moustafa Ayad, Research Chair in Global Islamism and Counter-Terrorism, and Bret Schafer, Senior Director of Policy & Research, Information-Operations, summarize the last three months of ISD’s investigations and research relating to the conflict as covered by the New York Times, the Wall Street Journal and CBS News.

The ‘vibes’ of information warfare
Over the past decade, democracies have worked to build up their information defenses against the weaponization of social media and emerging technologies by hostile foreign states. Those efforts have largely focused on detecting and exposing foreign malign influence — a catchall term describing the intentional subversion of public debate through deception, distortion or the promotion of disinformation.
Iran’s informational approach during the ongoing war has challenged that paradigm. After the opening salvos of the war, when Iran-linked accounts regularly posted AI-generated manipulations and promoted outright falsehoods, Iranian government and pro-regime influence campaigns have found their greatest success not by deceiving audiences but by entertaining them. Blending sharp political satire and savvy pop-culture references, Iran has used LEGO-styled rap videos and AI-generated parodies to both soften its global image and effectively neuter traditional responses. As ISD Senior Research Manager Peter Benzoni wrote in Foreign Policy, “the result is incredibly effective propaganda that our entire toolkit was designed to miss.”
Our analysis of Iranian diplomatic accounts shows how Tehran’s embassies have embraced this approach, gaining remarkable numbers of followers and surging engagement. In the first 50 days of the conflict, Iranian embassy and diplomatic accounts on X (formerly Twitter) received a 30-fold increase in likes compared to the 50 days prior.

Targeted antisemitism and Ashab al-Yamin al-Islamiyah
Pro-Iranian activity during the conflict has also embraced darker elements of online discourse, most notably both implicit and explicit forms of antisemitism. Our investigation into two networks of pro-regime accounts that we dubbed BRICS4CLICKS and Verified4War found both praised Nazi Germany and Adolf Hitler while promoting antisemitic conspiracy theories. The networks gained a combined total of more than a billion views in the first month of the conflict.
A separate ISD analysis found that antisemitic posts increased by nearly 70 percent in the week immediately after the outbreak of the conflict compared to the week prior. It also found a spike in user-to-user antisemitic hate speech and in conspiracy theories about “Jewish elites” orchestrating the conflict.
The conflict has triggered a wave of offline attacks on Jewish communities in the UK and Europe. Eighteen of those attacks have been attributed to a nebulous, new group analyzed by ISD and connected to Iranian-backed proxy militias called Harakat Ashab al-Yamin al-Islamiyah (The Islamic Movement of the Companions of the Right, also known as HAYI). The group is allegedly the brainchild of Muhammad Baqer al-Saadi, a high-ranking member of Katai’b Hezbollah, an Iranian Revolutionary Guard Corps (IRGC)-backed Iraqi militia group with a history of launching attacks on US diplomatic and military installations in the Middle East. al-Saadi, arrested at an airport in Turkey, and transferred to American custody, was also close to IRGC leadership. This included the now deceased Qassem Soleimani, architect of the Iranian “forward-defense strategy”: this involved supporting, training and equipping militias and Iranian proxies across the Middle East. Katai’b Hezbollah, alongside Lebanese Hezbollah, were considered the crown jewels of that strategy.
More ISD Research in the Media
The arrest of al-Saadi tells us a lot about Iranian external operations and their hybridized nature. Operating across platforms, and through proxies of proxies, al-Saadi used accounts reportedly linked to him on Telegram, Snapchat, X and Facebook to promote attacks on American and Israeli interests. At the start of the Israeli-US joint strikes on Iran, al-Saadi wrote to “kill everyone who supports America and Israel. Do not leave any of them remaining. Civil and military targets, as well as voices of discord, kill them everywhere.” The US Department of Justice alleges that al-Saadi then began a concerted effort bent on the “planning, execution, and promotion” of attacks in Europe. During that time, al-Saadi reportedly also called for the death of US President Donald Trump and promoted Ashab al-Yamin calls for attacks on the president and his family.
Katai’b Hezbollah’s Ashab al-Yamin used Snapchat to communicate via third-party interlocutors. They organised for unwitting assailants to conduct attacks on those targets, also turning to organized criminal networks to carry out planned attacks. Through a confidential informant, the US government learned that al-Saadi called Ashab al-Yamin “our people” and took credit for attacks in Europe and Canada while planning similar attacks in the US. The strategy here was what ISD analysts describe as “violence-as-a-service”: it relies on financially motivated individuals who are disproportionately young (including minors) and are recruited through encrypted messaging platforms such as Snapchat and Telegram.
The deliberately disposable nature of Ashab al-Yamin’s operational structure is what made it difficult to track. The most prominent thread between the attacks, as officials noted, was the use of young people as proxies. This attack architecture closely mirrors Russian hybrid tactics deployed against European states. Two of the Resistance Axis Telegram channels identified as primary sources for Ashab al-Yamin content were also tied to sanctioned Russian networks.
Hybrid deterrence and a joined-up response
The convergence of state-directed violence, criminal infrastructure and antisemitic targeting into a single operational model represents a turning point in the threat environment facing communities across the continent. Authorities have typically treated hostile state activity, terrorism, extremism and organised crime as distinct policy and operational problems. However, these adversaries increasingly exploit the same recruitment mechanisms and online tactics.
Enhanced awareness and coordination between different prongs of government, law enforcement and social media platforms is essential to effectively mitigate the rising impacts of this new form of hybridized warfare. However, without a comprehensive strategy for hybrid deterrence, the case for which ISD’s Sasha Havlicek and David Salvo make in their recent policy brief, democratic governments will continue to be on the back foot in relation to a mounting barrage of cyber, information and kinetic attacks.









