Threats Feed
- Public
SloppyMIO: AI-Assisted Malware Campaign Exploits Iran's Dey 1404 Unrest
The RedKitten campaign, observed in early 2026, targets Iranian interests, specifically NGOs and individuals documenting human rights abuses during the "Dey 1404" protests. Assessing the actor as Iranian state-aligned, researchers identified "SloppyMIO," a modular .NET implant likely developed with AI assistance. The attack chain utilizes spearphishing with "shock lures" regarding execution lists to deliver malware via AppDomainManager injection. The threat actor leverages legitimate infrastructure, using GitHub as a Dead Drop Resolver for steganographic configuration, Google Drive for payload hosting, and Telegram for command and control. This campaign highlights the growing use of LLMs in rapid malware development and the exploitation of civil unrest for targeted surveillance in Iran.
read more about SloppyMIO: AI-Assisted Malware Campaign Exploits Iran's Dey 1404 Unrest - Public
Iranian APTs Link Cyber Reconnaissance to Real-World Missile Strikes
Amazon’s threat intelligence team has identified a growing trend in which nation-state actors integrate cyber operations directly into kinetic warfare. The research highlights Imperial Kitten and MuddyWater, two Iranian-linked groups that used cyber intrusions to support physical attacks. Imperial Kitten compromised AIS maritime systems and CCTV feeds to track vessels later targeted by Houthi missile strikes. MuddyWater accessed live CCTV streams in Jerusalem, providing real-time intelligence ahead of Iran’s June 2025 missile attacks. These cases show a shift toward cyber-enabled kinetic targeting, where digital reconnaissance directly informs physical military objectives, reshaping modern conflict across the Middle East’s maritime and urban environments.
read more about Iranian APTs Link Cyber Reconnaissance to Real-World Missile Strikes - Public
Imperial Kitten's Middle East Cyber Campaign: Transport and Tech Sectors Targeted
CrowdStrike's investigation into Imperial Kitten's cyber activities reveals targeted cyberattacks and strategic web compromise (SWC) operations against transportation, logistics, and technology sectors, primarily in the Middle East. These attacks, spanning from early 2022 to 2023, involved the use of compromised websites, phishing, and malware like IMAPLoader and StandardKeyboard for initial access and persistence. Techniques such as SQL injection, the use of public exploits, and credential theft were employed. The operations leveraged tools like PAExec and NetScan for lateral movement and credential harvesting. IMPERIAL KITTEN also used custom malware and open-source tools for data exfiltration, with some utilizing Discord for command and control communications.
read more about Imperial Kitten's Middle East Cyber Campaign: Transport and Tech Sectors Targeted - Public
Yellow Liderc's Multi-Faceted Cyber Campaign Targets Global Industries
Yellow Liderc, a persistent threat actor, has been actively targeting industries including maritime, shipping and logistics in the Mediterranean, as well as aerospace, defense, and IT managed service providers in the US, Europe, and the Middle East. Their recent activities involve strategic web compromises to fingerprint website visitors and deploy a new .NET malware, IMAPLoader. This malware uses email for command and control and delivers additional payloads. It employs 'AppDomain Manager Injection' for execution. Concurrent phishing campaigns distribute a malicious Excel file containing a basic Python backdoor. The focus remains heavily on the maritime, shipping, and logistics sectors.
read more about Yellow Liderc's Multi-Faceted Cyber Campaign Targets Global Industries