< ciso
brief />
Tag Banner

All news with #iran nexus tag

87 articles

Tortoiseshell expands toolkit with backdoor, SSH tunnel

🛡️ Group-IB identified new Tortoiseshell activity, uncovering a reverse SSH tunneling utility and a C++ backdoor disguised as wtsapi32.dll. The SSH tool leverages Windows OpenSSH to create reverse tunnels into compromised networks, while the backdoor supports HTTPS C2 communications, file and shell execution, and in-memory DLL loading. Researchers also linked domains resolving to servers with regional subdomains, suggesting possible targeting across Europe and the Middle East and urging enhanced threat hunting and monitoring.
read more →

US Treasury Targets Iran-Linked Cyber Actors

🛡️ The U.S. Department of the Treasury announced Operation Economic Outcast, imposing sanctions on nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks. The measures target an MOIS-affiliated cyber group accused of widespread compromises of U.S. critical infrastructure and financially motivated theft, and designate five individuals tied to the Tehran-based Mabna Institute. Treasury and partner agencies emphasized cutting Iran's financial lifelines, while the State Department’s Rewards for Justice offers up to $10 million for information on malicious cyber actors.
read more →

US Imposes Sanctions Targeting Mabna Cyber Unit

🔒 The US announced Operation Economic Outcast on August 24, targeting nearly 60 individuals and entities to disrupt financial flows sustaining Iran. Five people linked to the Mabna Institute were sanctioned, following a Department of Justice indictment of 17 alleged members for long-running cyber-espionage. OFAC also published 30 crypto addresses tied to four defendants, with blockchain analysis tracing roughly $16.8m of funds. The measures expand sectoral sanctions, increasing compliance burdens for crypto and financial firms.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →

US Charges Iranian Hackers in Massive IP Theft Case

🛡️ The U.S. Justice Department charged eight additional alleged members of the Mabna Institute, bringing the total to 17 Iranians accused of a years-long campaign that stole academic research, intellectual property, emails, and proprietary data from U.S. and international organizations. The DoJ says the operation began around 2013 and compromised roughly 8,000 accounts—targeting over 100,000 professors worldwide—and extracted about 31.5 TB of data valued at $3.4 billion. Rewards of up to $10 million are offered for information on five defendants, and the defendants face multiple charges including conspiracy and aggravated identity theft.
read more →

Cavern C2 evolves, abusing DNS and Google Apps

🔍 Kaspersky researchers uncovered new components of the Cavern (CAV3RN) command-and-control framework used by Iranian-linked operators to target Israeli entities, revealing a module that switches between direct HTTPS and a Google Apps Script relay using DNS A-record responses. The modular toolkit supports extensive post-exploitation functions and minimizes forensic visibility, while additional reports show HOLLOWGRAPH abusing Microsoft 365 calendars and DNS tunneling to maintain and refresh Azure AD credentials. The findings highlight a shift to a plugin-based architecture and continued use of legitimate services to evade detection.
read more →

Preliminary Attribution of Water System Cyberattacks

⚠️ Reports indicate a campaign of cyber intrusions affecting water systems across multiple U.S. states, with at least seven states targeted and preliminary attribution to Iran. Authorities say no significant physical damage has been observed so far. Political leaders have publicly disputed the attribution, and discussion continues in technical and public forums.
read more →

GigaWiper: Multipurpose Windows backdoor and wiper

🛡️ Microsoft dissected a destructive Windows backdoor dubbed GigaWiper, which bundles three older wipers into a single Go-based platform offering selectable destructive commands. The implant can wipe entire disks, overwrite the Windows drive, or run fake ransomware that encrypts files without saving keys, and also provides remote control capabilities like screenshots, VNC access, and process management. Microsoft and Binary Defense observed the same file hashes and command servers, with Binary Defense linking the samples to an Iran-linked actor while Microsoft refrains from attributing a country. Defenders should monitor for a OneDrive Update scheduled task, RabbitMQ/Redis traffic from desktops, and suspicious use of takeown/icacls, and apply tamper protection, endpoint blocking, and blocklisted server addresses.
read more →

New Iran-linked hacking group targets Israeli IT

🛡️ Check Point Research has identified a new Iran-linked cyber threat group, dubbed Cavern Manticore, targeting Israeli government and IT organizations since early 2026. The group leverages abused RMM tools and browser-based remote desktop features for initial access and persistence, often deploying malicious updates via SysAid. Researchers observed a previously undocumented modular .NET-based C2 framework composed of a persistent Cavern agent and specialized Cavern modules, designed to evade detection and hinder forensic analysis.
read more →

Iran-linked MuddyWater Poses as Chaos Ransomware

🔍 Analysis by NCC Group reveals Iran-linked MuddyWater impersonated the Chaos ransomware group to mask espionage operations. The report, published June 24, details how operators used extortion notes, negotiation channels and a leak site listing to simulate a financially motivated attack. Researchers warn that state-backed actors increasingly adopt cybercriminal tradecraft, complicating detection and response.
read more →

US Sanctions Nobitex Exchange Over Ties to IRGC

🛡️ The U.S. Treasury's OFAC has sanctioned Nobitex, Iran's largest crypto exchange, accusing it of facilitating payments for terrorist activities and sanctions evasion. The designation names several Nobitex executives and founders and is part of the broader "Economic Fury" campaign that also targets Wallex, Bitpin, and Ramzinex. OFAC cites Chainalysis data showing Iran's crypto ecosystem received nearly $7.8 billion in 2025, with IRGC-linked addresses receiving over half of Q4 inflows. Sanctions freeze U.S.-jurisdiction assets and bar U.S. persons from transacting with the designated entities.
read more →

Law enforcement seizes hosting tied to Iranian campaigns

🔎 On May 22, 2026, Dutch investigators seized roughly 800 servers from WorkTitans B.V., a hosting provider that allegedly operated as a successor to a sanctioned ISP. The seized infrastructure supported multiple Iranian cyber espionage groups—MuddyWater, Agrius (UNC2428), and Nimbus Manticore—each using the provider for command-and-control, lure hosting, and scanning. This takedown disrupted active operations and highlights the need to evaluate hosting environments, ASNs, and passive DNS history rather than relying solely on individual IP flags.
read more →

Attack Surface and Cyber Risks for FIFA 2026

📘 The 2026 FIFA World Cup spans 39 days across 16 host cities in three nations, creating a vast temporary tournament network layered on existing stadium and municipal infrastructure. This assessment warns of high likelihoods for disruptive intrusions, large-scale fraud and politically motivated DDoS and hack-and-leak operations. Key drivers include Iran-nexus disruptive campaigns, pro-Russian hacktivist DDoS activity and financially motivated cybercrime targeting fans and the hospitality ecosystem.
read more →

ESET APT Activity Report Q4 2025–Q1 2026

📄 ESET summarizes notable APT activity observed between October 2025 and March 2026, highlighting China-, Iran-, North Korea-, and Russia-aligned operations alongside unattributed clusters. The report illustrates geopolitical drivers behind campaigns, describes new tooling and supply-chain compromises such as a trojanized axios package, and notes destructive incidents impacting critical infrastructure. ESET confirms protections by its products and notes the report reflects a subset of its Threat Intelligence.
read more →

AI-Enabled Sanctions Evasion Raises Governance Risks

🛡️ New RUSI research warns that adversaries, notably North Korea and Iran, are moving from AI-assisted to AI-enabled sanctions evasion and proliferation financing. The report highlights AI’s ability to mass-produce fraudulent documents, automate shell-company administration, and analyze blockchain flows to evade detection. Experts urge enterprises to adopt behavior-based analytics, defensive AI, stronger identity verification and updated training to counter these evolving threats.
read more →

Iranian Hackers Target Major South Korean Electronics Maker

🔒 Symantec researchers attribute a February 2026 cyber-espionage campaign to MuddyWater (Seedworm), which spent a week inside a major South Korean electronics manufacturer's network. The attackers relied on DLL sideloading of legitimate binaries — Fortemedia's fmapp.exe and SentinelOne's sentinelmemoryscanner.exe — to load malicious DLLs containing ChromElevator. They used PowerShell (now invoked via Node.js loaders) for reconnaissance, credential theft, persistence and SOCKS5 tunneling, and exfiltrated data via sendit.sh.
read more →

Iranian Spies Masquerade as Ransomware to Mask Espionage

🕵️ State-aligned Iranian operatives are posing as a ransomware affiliate to conceal espionage and cyber-sabotage, according to research by Rapid7. The group, linked to MuddyWater (aka Seedworm), impersonated the Chaos ransomware-as-a-service brand while using social engineering over Microsoft Teams—including interactive screensharing—to harvest credentials and bypass MFA. Operators used remote management tools like DWAgent for persistence and followed intrusions with extortion messaging and leak-site posts, but prioritized data exfiltration over encryption.
read more →

Iran-Linked APT Mimicked Chaos Ransomware in Espionage

🛡️ Rapid7 says an Iranian government-linked APT posed as a Chaos ransomware affiliate to mask espionage and prepositioning in an intrusion in early 2026. The actor, identified as MuddyWater (aka Seedworm/Static Kitten/Mango Sandstorm), used interactive Microsoft Teams social engineering to harvest credentials and manipulate MFA. They established persistence with DWAgent and AnyDesk, exfiltrated data, and initiated extortion negotiations without deploying a ransomware payload.
read more →

MuddyWater Employs Microsoft Teams for Targeted Intrusion

🔐 Rapid7 attributes a deception-driven intrusion to the Iranian-affiliated actor MuddyWater, which used Microsoft Teams social engineering to harvest credentials and manipulate MFA via live screen-sharing. Once inside, operators leveraged compromised accounts, remote-access tools like DWAgent and AnyDesk, and a trojanized WebView2 binary to maintain persistence and exfiltrate data rather than encrypt files. The campaign appears to have intentionally mimicked RaaS artefacts — including Chaos-related extortion indicators and a signed loader — to obscure state-backed motives and slow incident response.
read more →

Handala Hackers Leak US Marines' Data, Send Threats

🚨 US Marines stationed near the Persian Gulf reported receiving chilling WhatsApp messages beginning Monday that urged them to call home and make final goodbyes. The messages were signed by the Iran-linked Handala hacking group and allegedly originated from a Bahraini phone number that was likely spoofed or hijacked. A day later, Handala posted that it had published names and phone numbers of 2,379 Marines and boasted of possessing addresses, family details and daily routines. While authorities caution that such claims may rely on scraped or recycled data rather than a fresh breach, the campaign’s intent to intimidate service members is clear.
read more →