Latest Update27/08/2026

Threats Feed

  1. Public

    TAG-182 Deploys MarkiRAT in Escalating Iranian Surveillance Campaigns

    The Iran-nexus threat cluster TAG-182 is actively disseminating MarkiRAT malware to conduct digital surveillance against Iranian citizens, dissidents, and anti-government networks located in Iran, Europe, and North America. Capitalizing on Iran's recent internet restoration, the group distributes the malware by disguising it as legitimate applications, such as fake VPNs and media players, promoted through Farsi-language social media lures. TAG-182 utilizes infrastructure masking as well-known tech services to facilitate command and control. These operations are highly likely part of a broader Iranian state-sponsored initiative involving multiple security organizations aimed at suppressing domestic unrest and monitoring civil society sectors through intensified cyber espionage.

    read more about TAG-182 Deploys MarkiRAT in Escalating Iranian Surveillance Campaigns
  2. Public

    Cyber Isnaad Front: The Destructive IT/OT Convergence in Israeli Critical Sectors

    An Iranian state-directed persona, Cyber Isnaad Front (linked to IRGC-affiliated ASA), has been conducting destructive cyber operations against Israeli industry under the cover of a kinetic ceasefire. Targeting the defense, telecom, logistics, and food production sectors, the actor demonstrates a dangerous convergence of IT and OT capabilities. On IT networks, they deploy the Go Remote Access Toolkit (GRAT) disguised as Microsoft updates to execute devastating disk wipes. Concurrently, in OT environments, the attackers perform deep physical sabotage, such as reprogramming industrial CO2 refrigeration controllers to destroy mechanical compressors. This campaign leverages a hack-and-leak facade to obscure its true intent: deniable physical and digital destruction.

    read more about Cyber Isnaad Front: The Destructive IT/OT Convergence in Israeli Critical Sectors
  3. Public

    Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning

    During the 2026 Operation Epic Fury, the IRGC-affiliated threat actor Nimbus Manticore (UNC1549) launched sophisticated cyber campaigns targeting the aviation, software, defense, and telecommunication sectors across the United States, Europe, Australia, and the Middle East (specifically Israel, Saudi Arabia, and the UAE). The group demonstrated rapid capability evolution by deploying a new AI-assisted backdoor named MiniFast. Attackers leveraged AppDomain Hijacking, trojanized Zoom installers, and SEO poisoning to deliver malware via fake SQL Developer download sites and career-themed phishing lures. These operations highlight Nimbus Manticore's high adaptability and continuous development of advanced stealth and persistence mechanisms amid the Iranian conflict.

    read more about Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning
  4. Public

    Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft

    In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.

    read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
  5. Public

    False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand

    In early 2026, the Iranian state-sponsored APT MuddyWater executed a sophisticated false-flag operation masquerading as a Chaos ransomware attack. Primarily targeting the United States, Israel, and MENA organizations—specifically within the construction, manufacturing, and business services sectors—the group bypassed traditional encryption. Instead, they focused on data exfiltration and long-term espionage. Initial access was achieved via Microsoft Teams social engineering, enabling interactive credential harvesting and MFA manipulation. Attackers established persistence using legitimate remote access tools like DWAgent alongside a custom trojanized WebView2 RAT. Analysis of C2 infrastructure and an MOIS-linked code-signing certificate confirmed the attribution. This hybrid intrusion highlights how state actors increasingly leverage cybercriminal RaaS branding to obscure intelligence-gathering operations.

    read more about False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand
  6. Public

    Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records

    An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.

    read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
  7. Public

    Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive

    APT-C-49 (OilRig), an Iranian state-sponsored threat group, recently launched a sophisticated phishing campaign utilizing Iranian protest-themed Excel lures. Targeting government, finance, energy, telecommunications, and military sectors across the Middle East, US, Europe, and Asia, the group deployed a highly covert, multi-stage attack chain. The infection begins with macro-driven C# compilation, progressing to dead-drop resolving via GitHub. The payload utilizes LSB steganography on Google Drive-hosted images to extract encrypted configurations. Subsequently, it dynamically loads fileless modules into memory for data theft and remote execution, leveraging the Telegram Bot API for encrypted command and control (C2). This campaign highlights OilRig's evolution toward cloud service abuse and in-memory execution to evade detection.

    read more about Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive
  8. Public

    DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities

    DinDoor, a modular Tsundere botnet variant linked to state-sponsored actors like MuddyWater and cybercrime clusters, exploits the Deno runtime to execute obfuscated JavaScript, effectively bypassing traditional endpoint detections. Delivered via deceptive MSI files, recent campaigns have targeted U.S. organizations and the Russian financial services sector. Upon execution, the malware binds a local port as a mutex, aggressively fingerprints the victim’s hardware, and communicates with a multi-tenant command and control (C2) infrastructure, notably serialmenot[.]com. By analyzing unique Caddy proxy HTTP response headers, researchers identified 20 active C2 servers. Ultimately, DinDoor demonstrates how threat actors increasingly abuse trusted, signed runtimes and shared backend platforms to conceal their operations.

    read more about DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities
  9. Public

    MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization

    Oasis Security analyzed a multi-stage campaign attributed with medium-to-high confidence to MuddyWater, targeting critical infrastructure organizations across the Middle East — primarily Egypt, Israel, and the UAE — as well as Portugal and India. The operation began with large-scale automated reconnaissance, scanning more than 12,000 internet-exposed systems for five newly disclosed vulnerabilities affecting web applications, email servers, IT management platforms, and workflow automation tools. Following this broad scanning phase, the actor shifted to selective, high-value targeting: brute-forcing Outlook Web Access (OWA) credentials using custom tooling and multi-threaded frameworks such as Patator, with confirmed credential harvesting against organizations in Egypt, Israel, and the UAE. A modular, multi-protocol command-and-control (C2) infrastructure hosted in the Netherlands was used to manage compromised hosts, leveraging TCP, UDP, and HTTP channels with AES-encrypted communications — patterns consistent with the ArenaC2 framework previously associated with MuddyWater. The campaign resulted in confirmed exfiltration of sensitive data from an Egyptian aviation organization, including passport and visa records, payroll data, credit card information, and internal corporate documents. Approximately 200 files were staged in attacker-controlled directories prior to exfiltration, indicating structured data collection. The operation's timing — beginning in early February 2026, ahead of escalating regional tensions — suggests alignment with broader Iranian strategic intelligence objectives.

    read more about MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization
  10. Public

    MuddyWater's Operation Olalampo: Uncovering C2 Infrastructure and Telegram Bot Utilization in MENA Targets

    The APT group MuddyWater recently launched "Operation Olalampo," targeting organizations and individuals primarily across the MENA region amidst ongoing geopolitical tensions. In this campaign, the threat actors deployed newly developed malware variants and utilized Telegram bots for Command and Control (C&C) operations. A deep dive into the campaign's infrastructure revealed the use of recently registered, Namecheap-administered domains localized in Iceland, routing through US-geolocated IP addresses. Further DNS and threat intelligence analysis uncovered a vast network of over 2,500 connected domains linked to a single registrant email, along with active communications originating from ten potential victim IP addresses.

    read more about MuddyWater's Operation Olalampo: Uncovering C2 Infrastructure and Telegram Bot Utilization in MENA Targets
  11. Public

    MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage

    Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.

    read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
  12. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  13. Public

    Iran-Linked Threat Actor Targets Middle East Cloud Environments with Password Spraying

    An Iran-nexus threat actor conducted a sophisticated Microsoft 365 password-spraying campaign across three waves in March, primarily focusing on Israel and the UAE. Utilizing red-team tools and Tor exit nodes masquerading as Internet Explorer 10, the attackers circumvented atomic indicators to compromise weak credentials. Once successful, the actor bypassed geo-restrictions using Israeli-geolocated commercial VPNs to seamlessly log in and exfiltrate sensitive personal email data. The campaign heavily targeted local municipalities—assessed as likely supporting kinetic operations and bomb damage assessments—alongside the government, energy, aviation, maritime, and satellite sectors. Limited targeting was also observed in the US, UK, Europe, and Saudi Arabia.

    read more about Iran-Linked Threat Actor Targets Middle East Cloud Environments with Password Spraying
  14. Public

    OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor

    PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.

    read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
  15. Public

    HTTP_VIP Malware Profile: System Reconnaissance and RMM Payload Delivery

    HTTP_VIP is a downloader malware attributed to the Iranian state-aligned threat actor MuddyWater. Analyzed during the early-2026 campaign dubbed "Operation Olalampo," this tool functions primarily to establish a foothold on compromised systems. It executes system reconnaissance while employing virtualization and sandbox evasion techniques to bypass defensive analysis. Following successful execution, HTTP_VIP connects to its command and control infrastructure to retrieve secondary payloads. Notably, the threat actors utilize this downloader to deploy legitimate remote monitoring and management (RMM) software, specifically AnyDesk. The deployment of AnyDesk facilitates persistent remote access and control over the victim environments, blending malicious activity with standard administrative tools.

    read more about HTTP_VIP Malware Profile: System Reconnaissance and RMM Payload Delivery
  16. Public

    Iran MOIS Cyber Actors Deploy Telegram C2 Malware Against Global Dissidents and Journalists

    Iran Ministry of Intelligence and Security (MOIS) cyber actors are executing a global malware campaign targeting Iranian dissidents, journalists, and opposition groups. Using social engineering via messaging platforms, attackers deliver first-stage malware disguised as legitimate software, such as Telegram or KeePass. Upon execution, a persistent second-stage implant establishes a command-and-control channel via Telegram bots. This allows the attackers to harvest and exfiltrate sensitive data, including screen and audio captures from active Zoom sessions. Linked to proxy groups like "Handala Hack," these operations fuel hack-and-leak campaigns and deploy custom wiper malware. The attacks ultimately aim to conduct intelligence collection and inflict reputational damage on individuals threatening the Government of Iran's narratives.

    read more about Iran MOIS Cyber Actors Deploy Telegram C2 Malware Against Global Dissidents and Journalists
  17. Public

    TA453 Maintains Credential Phishing Operations Against US Think Tanks Amid Middle East Conflict

    Despite an internet shutdown following US and Israeli military strikes in late February 2026, the Iran-aligned threat actor TA453 (Charming Kitten) maintained its targeted espionage operations. Continuing an effort initiated prior to the conflict, TA453 targeted an individual at a US-based think tank. The attackers spoofed a researcher from the Henry Jackson Society, sending spearphishing emails themed around a Middle East air defense roundtable. To build rapport, the threat actor initially shared a benign document via OneDrive. Once trust was established, TA453 delivered a malicious link that redirected the target to a custom OneDrive-themed credential phishing page hosted on Netlify to harvest their credentials.

    read more about TA453 Maintains Credential Phishing Operations Against US Think Tanks Amid Middle East Conflict
  18. Public

    Boggy Serpens Evolves Tactics: Hijacked Accounts and AI-Enhanced Malware Targeting Critical Infrastructure

    Iranian state-sponsored actor Boggy Serpens has escalated cyberespionage campaigns against energy, maritime, finance, aviation, and diplomatic sectors across the Middle East, Europe, Asia, and South America, notably targeting Israel, the UAE, and Turkmenistan. By hijacking trusted corporate and government email accounts, the group bypasses perimeter defenses to deliver highly tailored spear-phishing lures. Recent operations reveal a strategic shift toward stealth and long-term persistence. The group has modernized its toolkit using AI-assisted development, deploying sophisticated custom implants like the Rust-based BlackBeard backdoor, UDPGangster, Nuso, and LampoRAT. To evade detection, Boggy Serpens utilizes evasive C2 mechanisms, including Telegram API abuse, customized UDP traffic, and HTTP status code triggers, cementing its status as a highly adaptable and formidable threat.

    read more about Boggy Serpens Evolves Tactics: Hijacked Accounts and AI-Enhanced Malware Targeting Critical Infrastructure
  19. Public

    Handala Hack: Unpacking Void Manticore’s Destructive Wiping and Hack-and-Leak Operations

    Handala Hack, an Iranian MOIS-affiliated threat actor also tracked as Void Manticore, executes destructive wiping and hack-and-leak operations against targets in Israel, Albania, and the United States. They primarily target the government, telecommunications, and medical technology sectors. The group relies on compromised VPN accounts for initial access, subsequently moving laterally via RDP and the zero-trust mesh platform NetBird. Their hands-on attacks involve disabling Windows Defender and conducting extensive credential dumping via LSASS extraction and ADRecon. To maximize operational impact, Handala simultaneously deploys custom MBR and PowerShell wipers via Group Policy, leverages VeraCrypt for disk encryption, and manually deletes virtual machines, causing severe data destruction.

    read more about Handala Hack: Unpacking Void Manticore’s Destructive Wiping and Hack-and-Leak Operations
  20. Public

    Iranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations

    Iranian Ministry of Intelligence and Security (MOIS)-linked threat actors, such as Void Manticore and MuddyWater, are actively integrating cybercriminal tools and affiliate networks into their state-sponsored operations. Moving beyond merely using cybercrime as a cover for deniability, these groups are leveraging commercial infostealers like Rhadamanthys, malware-as-a-service networks like CastleLoader, and the Qilin ransomware-as-a-service (RaaS) to enhance their operational reach and obfuscate attribution. Recent campaigns have targeted government and private sectors, including telecommunications, defense, energy, and medical facilities—across the Middle East, Israel, Albania, and the United States. Notably, these operations have utilized ransomware branding to execute destructive and extortion attacks against Israeli hospitals, fulfilling strategic state objectives through the criminal ecosystem.

    read more about Iranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations
  21. Public

    MuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs

    Huntress researchers have detailed a complete attack chain attributed to the Iranian-linked APT MuddyWater, targeting an Israeli company. The intrusion began with initial access via an RDP login, followed by extensive interactive network and Active Directory reconnaissance. The threat actor demonstrated hands-on-keyboard activity, evidenced by typographical errors during command execution. To establish persistent access and bypass network controls, the attackers utilized the native Windows OpenSSH client to create reverse SSH tunnels. Subsequently, they deployed a malicious payload via DLL side-loading, leveraging the legitimate Fortemedia application (FMAPP.exe) to execute a malicious DLL (FMAPP.dll) for command-and-control communications.

    read more about MuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs
  22. Public

    Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors

    The Iranian APT group Seedworm has targeted multiple organizations across the U.S., Canada, and Israel since February 2026. Leveraging custom malware, the threat actors compromised networks within the financial, aviation, software, defense, and non-profit sectors. Attackers deployed a novel JavaScript/TypeScript backdoor named Dindoor, alongside a Python-based backdoor called Fakeset. To evade detection, the group signed their payloads with digital certificates issued to "Amy Cherne" and "Donald Gay." Additionally, the attackers utilized legitimate cloud services, including Backblaze for staging and Rclone for attempted data exfiltration to Wasabi buckets. Given Seedworm’s affiliation with the Iranian Ministry of Intelligence and Security, these intrusions pose a significant espionage threat amidst current geopolitical conflicts.

    read more about Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors
  23. Public

    Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure

    Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.

    read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
  24. Public

    Dust Specter: Iran-Nexus APT Targets Iraqi Government via Custom .NET Malware

    In January 2026, the Iran-nexus threat actor Dust Specter launched a targeted cyber espionage campaign against Iraqi government officials, specifically impersonating the Ministry of Foreign Affairs. Utilizing compromised government infrastructure, the group deployed undocumented .NET-based malware, including the SPLITDROP dropper and the TWINTASK/TWINTALK backdoors. The operation is characterized by sophisticated DLL side-loading techniques using legitimate binaries like VLC and WingetUI. A secondary attack chain features GHOSTFORM, a consolidated RAT that employs invisible Windows forms for delayed execution and in-memory PowerShell scripts to minimize its forensic footprint. Evidence suggests the actors leveraged generative AI to streamline code development and implemented "ClickFix" social engineering tactics to compromise targets.

    read more about Dust Specter: Iran-Nexus APT Targets Iraqi Government via Custom .NET Malware