A reported campaign tied to an Iran-linked actor shows how a modular command-and-control stack and a foothold in IT service providers can turn trust into an attack path.