A different try to analyze and simplify threat intelligence

Threats Feed

We are excited to announce that the preliminary editions of Threats Feed and Actors Insights are now accessible to the public. Our efforts are focused on incorporating additional practical features and beneficial resources with the intention of nurturing an informed community. Stay connected for further updates.

  1. TAG-182 Deploys MarkiRAT in Escalating Iranian Surveillance Campaigns

    The Iran-nexus threat cluster TAG-182 is actively disseminating MarkiRAT malware to conduct digital surveillance against Iranian citizens, dissidents, and anti-government networks located in Iran, Europe, and North America. Capitalizing on Iran's recent internet restoration, the group distributes the malware by disguising it as legitimate applications, such as fake VPNs and media players, promoted through Farsi-language social media lures. TAG-182 utilizes infrastructure masking as well-known tech services to facilitate command and control. These operations are highly likely part of a broader Iranian state-sponsored initiative involving multiple security organizations aimed at suppressing domestic unrest and monitoring civil society sectors through intensified cyber espionage.

    read more about TAG-182 Deploys MarkiRAT in Escalating Iranian Surveillance Campaigns
  2. Cyber Isnaad Front: The Destructive IT/OT Convergence in Israeli Critical Sectors

    An Iranian state-directed persona, Cyber Isnaad Front (linked to IRGC-affiliated ASA), has been conducting destructive cyber operations against Israeli industry under the cover of a kinetic ceasefire. Targeting the defense, telecom, logistics, and food production sectors, the actor demonstrates a dangerous convergence of IT and OT capabilities. On IT networks, they deploy the Go Remote Access Toolkit (GRAT) disguised as Microsoft updates to execute devastating disk wipes. Concurrently, in OT environments, the attackers perform deep physical sabotage, such as reprogramming industrial CO2 refrigeration controllers to destroy mechanical compressors. This campaign leverages a hack-and-leak facade to obscure its true intent: deniable physical and digital destruction.

    read more about Cyber Isnaad Front: The Destructive IT/OT Convergence in Israeli Critical Sectors
  3. Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning

    During the 2026 Operation Epic Fury, the IRGC-affiliated threat actor Nimbus Manticore (UNC1549) launched sophisticated cyber campaigns targeting the aviation, software, defense, and telecommunication sectors across the United States, Europe, Australia, and the Middle East (specifically Israel, Saudi Arabia, and the UAE). The group demonstrated rapid capability evolution by deploying a new AI-assisted backdoor named MiniFast. Attackers leveraged AppDomain Hijacking, trojanized Zoom installers, and SEO poisoning to deliver malware via fake SQL Developer download sites and career-themed phishing lures. These operations highlight Nimbus Manticore's high adaptability and continuous development of advanced stealth and persistence mechanisms amid the Iranian conflict.

    read more about Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning
  4. Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft

    In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.

    read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft