Latest Update27/08/2026

Threats Feed

  1. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  2. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  3. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  4. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  5. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  6. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  7. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  8. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  9. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  10. Public

    Global Financial Executives Hit by Multi-Stage Phishing Operation

    A sophisticated spear-phishing campaign targeted CFOs and finance executives in banking, energy, insurance, and investment sectors across the UK, Canada, South Africa, Norway, South Korea, Singapore, Switzerland, France, Egypt, Saudi Arabia, and Brazil. Disguised as a Rothschild & Co recruiter, the attackers used Firebase-hosted phishing pages protected by custom CAPTCHAs to deliver multi-stage payloads. Victims who executed malicious VBS scripts unknowingly installed NetBird and OpenSSH, granting attackers persistent, encrypted remote access through hidden admin accounts and RDP activation. Trellix researchers identified infrastructure overlaps with previous nation-state campaigns but withheld attribution.

    read more about Global Financial Executives Hit by Multi-Stage Phishing Operation
  11. Public

    Fake Assassination News Used in Phishing Attack Impersonating The New York Times

    A phishing campaign is exploiting sensational fake news about an assassination attempt on US President-elect Donald Trump by an Iranian sniper. The campaign poses as The New York Times using the email address newyork-times@nycmail[.]com. Victims who click on the embedded link are redirected to an ESET-imitation phishing site, where they are prompted to enter corporate domain credentials. This campaign is an example of attackers using major global events, such as political elections, to amplify their efforts. The use of urgency and sensational headlines highlights the need for vigilance in verifying information.

    read more about Fake Assassination News Used in Phishing Attack Impersonating The New York Times
  12. Public

    Brute Force and MFA Push Bombing Tactics Used in Iranian Cyber Campaign

    Iranian cyber actors targeted critical infrastructure sectors in the US, Canada, and Australia, including healthcare, government, energy, and IT organisations. The attackers used password spraying and MFA push bombing to obtain valid accounts and access systems such as Microsoft 365, Azure, and Citrix. They used open source tools to gain access to credentials, including Kerberos SPN enumeration and Active Directory dumps. In some cases, the attackers attempted to exploit the Netlogon vulnerability for privilege escalation. In addition, the actors used discovery techniques using living-off-the-land tools to identify domain controllers, trusted domains and administrative accounts.

    read more about Brute Force and MFA Push Bombing Tactics Used in Iranian Cyber Campaign
  13. Public

    Malware Masquerading as Palo Alto GlobalProtect Targets Middle Eastern Organizations

    Threat actors are targeting users in the Middle East with malware disguised as the Palo Alto GlobalProtect VPN tool. Delivered likely through phishing, the malware employs a two-stage infection chain initiated via a malicious setup.exe. It uses advanced command-and-control (C2) infrastructure, including newly registered domains like “sharjahconnect” and the Interactsh project for beaconing. Written in C#, the malware supports remote PowerShell execution, file download/exfiltration, and AES-encrypted communications. It also features sandbox evasion, system information gathering, and beaconing mechanisms to track infection stages. This campaign highlights significant threats to organizations in the region, particularly those reliant on VPN-based remote access.

    read more about Malware Masquerading as Palo Alto GlobalProtect Targets Middle Eastern Organizations
  14. Public

    State-Sponsored Cyberattacks Target Israeli Academia and Government Sectors

    Recent cyberattacks by state-sponsored groups have targeted Israeli organizations in academia, local government, and managed service providers (MSPs). These attacks aim to cause substantial damage by erasing critical data from servers and workstations using Microsoft's SDelete tool from the SYSInternals suite. The attackers leverage outdated VPN servers to gain initial access, followed by lateral movements within networks to reach their targets. Several organizations have already been impacted, predominantly through an attack on the supply chain, hindering data restoration efforts.

    read more about State-Sponsored Cyberattacks Target Israeli Academia and Government Sectors
  15. Public

    Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation

    In December, an Iranian attack group launched a phishing campaign impersonating F5 company to target Israeli economic sectors. The campaign aimed for destructive attacks and information gathering. It involved emails from a spoofed F5 address, containing links to download Wiper and Infostealer malware. The attack exploited an F5 critical warning, requiring users to run a Shell Script file. Malicious files included a .NET-based f5updater.exe for Windows and a Bash Script for Linux. These scripts, effective only with administrative privileges, were designed for data destruction and information stealing, with the latter employing advanced evasion techniques like AV service disabling and script obfuscation.

    read more about Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation
  16. Public

    Iranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack

    The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Cyber National Mission Force (CNMF) identified multiple APT actors exploiting vulnerabilities in an Aeronautical Sector organization as early as January 2023. The actors targeted a public-facing application (Zoho ManageEngine ServiceDesk Plus) and the organization’s firewall device, exploiting CVE-2022-47966 and CVE-2022-42475. They gained unauthorized access, established persistence, moved laterally, and engaged in defense evasion by deleting logs. Although the attackers achieved extensive network enumeration and credential access, the report didn't confirm any data exfiltration.

    read more about Iranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack
  17. Public

    WINTAPIX: New Kernel Driver Targets Middle Eastern Countries

    Fortinet researchers discovered WINTAPIX, a sophisticated Windows kernel driver suspected to be the work of Iranian threat actors, targeting IIS web servers across the Middle East — primarily in Saudi Arabia, with additional targeting of Jordan, Qatar, and the United Arab Emirates. Active since at least mid-2020, the malware remained largely undetected for years before significant spikes in activity emerged in August–September 2022 and February–March 2023. WINTAPIX operates at the kernel level, giving it deep system access and making it significantly harder to detect and remove than user-mode implants. The driver uses the open-source Donut framework to generate and inject shellcode that loads an obfuscated .NET payload into a target process. The payload — protected with SmartAssembly and Eazfuscator to resist reverse engineering — provides the operators with backdoor access and proxy functionality, enabling persistent remote control and traffic tunneling through the compromised IIS server. The driver itself is shielded with VMProtect, transforming its code into a virtualized format to hinder static analysis.

    read more about WINTAPIX: New Kernel Driver Targets Middle Eastern Countries
  18. Public

    Iranian APTs Exploit Log4Shell to Compromise FCEB Network

    In April 2022, CISA detected Iranian government-sponsored APT activity compromising an FCEB organization's network via the Log4Shell vulnerability. Initial exploitation targeted an unpatched VMware Horizon server, later spreading to the domain controller. The threat actors utilized PowerShell commands, disabled Windows Defender, and established persistence through scheduled tasks. Tools like Mimikatz and Ngrok were deployed for credential harvesting and C2 communication. Despite attempts to dump the LSASS process, additional anti-virus measures thwarted this activity. Lateral movement was observed, as were activities aimed at credential and account manipulation.

    read more about Iranian APTs Exploit Log4Shell to Compromise FCEB Network
  19. Public

    Iranian State-Sponsored Actors Exploit Log4Shell to Target US Government

    In April 2022, Iranian government-sponsored actors exploited the Log4Shell vulnerability in VMware Horizon servers, targeting a Federal Civilian Executive Branch (FCEB) organization. They installed XMRig crypto mining malware and used tools like Mimikatz and Ngrok for credential theft and tunneling. The attack involved disabling Windows Defender, downloading malicious files, hiding artifacts, and creating scheduled tasks for persistence. The campaign highlights advanced tactics in disabling security controls and maintaining persistent access. The targeted sector was the US government.

    read more about Iranian State-Sponsored Actors Exploit Log4Shell to Target US Government
  20. Public

    Sophisticated PowerShell Attack Targets Systems with Spearphishing

    The Fully Undetectable (FUD) PowerShell backdoor report details a sophisticated attack beginning with a malicious Word document ("Apply Form.docm") used in a LinkedIn-based spearphishing campaign originating from Jordan. The document contains a macro that launches a PowerShell script, creating a scheduled task to execute further malicious actions. The backdoor communicates with its C2 server, executing various commands such as process list exfiltration, user enumeration, and Active Directory exploration. SafeBreach identified operational security mistakes allowing decryption of the C2 commands. The campaign, involving PowerShell scripts and scheduled tasks, targets systems for data exfiltration and potential lateral movement.

    read more about Sophisticated PowerShell Attack Targets Systems with Spearphishing
  21. Public

    Iranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns

    Iranian Islamic Revolutionary Guard Corps-affiliated cyber actors exploited vulnerabilities in Fortinet FortiOS, Microsoft Exchange, and VMware Horizon applications since early 2021, targeting entities in the U.S., U.K., and Australia. These vulnerabilities, including CVE-2018-13379, CVE-2020-12812, CVE-2019-5591, and several ProxyShell issues, were used for initial access, ransom operations, and data exfiltration. Activities include encrypting data for ransom, extortion operations, and crypto-mining, impacting sectors like law enforcement, transportation, municipal government, and aerospace. The actors leveraged tools like FRP, Plink, RDP, and BitLocker for command and control, lateral movement, and encryption.

    read more about Iranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns
  22. Public

    CodeRAT Targets Farsi-Speaking Developers with Innovative C2 Techniques

    SafeBreach Labs has discovered CodeRAT, a new remote access trojan (RAT) targeting Farsi-speaking software developers with capabilities ranging from espionage to data exfiltration. Delivered via a Word document that exploits Microsoft DDE, CodeRAT monitors activity in various applications, particularly those related to social networking and development tools. Uniquely, it uses public file upload APIs and Telegram groups for command and control, bypassing typical C2 infrastructure. The malware supports 50 commands, including clipboard capture, process control and file upload. The CodeRAT developer released the source code on GitHub after it was discovered by researchers.

    read more about CodeRAT Targets Farsi-Speaking Developers with Innovative C2 Techniques
  23. Public

    Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers

    SafeBreach Labs discovered an Iranian threat actor exploiting the MSHTML vulnerability (CVE-2021-40444) to infect Farsi-speaking victims with the PowerShortShell stealer via spear phishing. The attack, first reported in September 2021, involved a malicious Word document connecting to a server, downloading a DLL, and executing a PowerShell script. This script collected data, including screenshots and files, and exfiltrated it to the attacker's server. The campaign targeted Iranians abroad, particularly in the United States, suggesting ties to Iran's Islamic regime.

    read more about Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers
  24. Public

    Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers

    SafeBreach Labs discovered an Iranian threat actor exploiting the MSHTML vulnerability (CVE-2021-40444) to infect Farsi-speaking victims with the PowerShortShell stealer via spear phishing. The attack, first reported in September 2021, involved a malicious Word document connecting to a server, downloading a DLL, and executing a PowerShell script. This script collected data, including screenshots and files, and exfiltrated it to the attacker's server. The campaign targeted Iranians abroad, particularly in the United States, suggesting ties to Iran's Islamic regime.

    read more about Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers