A midyear threat intelligence assessment of Iran-linked cyber activity during the ongoing conflict, covering the full ecosystem of Iranian state actors (MOIS, IRGC-IO, IRGC-CEC), their personas (Handala, Homeland Justice, Karma), and distinct mission sets. Key findings: the most durable strategic risk is access optionality — footholds gained for espionage can be repurposed for disruption as tasking changes. Persona operations function as reusable operational infrastructure combining intrusion, data theft, leaks, and psychological pressure. OT risk is real but evidence quality is often poor; an evidence ladder framework is proposed for evaluating cyber-physical claims. Inside Iran, shared-service concentration, connectivity controls, and limited disclosure create compounding risks. Defenders are advised to audit identity, RMM, and service-provider relationships, and OT operators should remove internet-exposed PLCs and enforce phishing-resistant MFA on remote access.