Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access
A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...
HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel
Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap...
Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework
A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check...
CyberAv3ngers: Iran-Linked IRGC Hackers Target Rockwell PLCs Across U.S. Critical Infrastructure
A joint CISA advisory warns that Iran-linked CyberAv3ngers (IRGC-CEC) are actively exploiting internet-exposed Rockwell Automation PLCs across U.S. water, energy, and government sectors. Over 5,200 devices are publicly...
MuddyWater-Linked APT Campaign Scanned 12,000+ Systems Before Striking Middle East Critical Infrastructure
Iran-linked threat group MuddyWater is behind a sophisticated espionage campaign that scanned over 12,000 systems in the Middle East before stealing passport records and payroll data from an...
SpearSpecter: Iran’s Patient, multi-layered targeting campaign
The cybersecurity landscape is increasingly characterized by sophistication, and the ongoing SpearSpecter campaign represents a particularly concerning evolution in state-sponsored espionage. This isn’t a blunt instrument of brute-force...
Unveiling UNC1860: Iran’s stealthy cyber threat
In the ever-evolving cybersecurity landscape, state-sponsored threat actors continue to pose significant risks to organizations worldwide. Among them is UNC1860, an Iranian-based cyber espionage group recently exposed by...
Escalating iranian cyber influence operations ahead of the 2024 US elections
As the 2024 US presidential election looms, the Microsoft Threat Analysis Center (MTAC) has unveiled an alarming uptick in cyber-enabled influence operations orchestrated by Iranian actors, marking a...