Related Threat Clusters
-
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Surge in Middle East Cyber Espionage Amid Ongoing Conflict
Following the outbreak of fighting involving Iran, there has been a significant increase in cyber espionage activities targeting governments and diplomatic missions across the Middle East. Research from Proofpoint…
1 article · Updated March 12, 2026 -
North Korea Adopts Modular Malware to Evade Detection and Takedowns
North Korea's cyber program has transitioned to a modular malware strategy, moving away from monolithic malware families to a more fragmented ecosystem. This change is a response to years of international sanctions, law…
3 articles · Updated April 6, 2026 -
New York Implements Cyber Regulations Amid Rising Threats to Water Facilities
On March 11, 2026, New York Governor Kathy Hochul announced new cybersecurity regulations for drinking water and wastewater facilities, following a previous announcement in summer 2025. These regulations, described as…
2 articles · Updated March 11, 2026 -
Iran Cyber Attack Involves APTs and Hacktivist Proxies
A coordinated cyber attack targeting Iran has been attributed to Advanced Persistent Threats (APTs) and hacktivist proxies. These groups, often state-funded, are known for executing sophisticated attacks on critical…
3 articles · Updated March 3, 2026 -
Iranian Cyber Espionage Targets US Academics and Policy Experts
Between June and August 2025, a previously unidentified Iranian cyber actor, dubbed UNK_SmudgedSerpent, conducted targeted phishing attacks against US academics and foreign policy experts. The campaign aimed to steal…
1 article · Updated November 10, 2025 -
RedKitten Campaign Targets Iranian Protest Monitors with AI Malware
The RedKitten campaign has emerged, utilizing AI-driven malware to target individuals and organizations monitoring human rights violations during the Dey 1404 protests in Iran. Discovered by HarfangLab, the campaign…
4 articles · Updated February 2, 2026 -
Charming Kitten: Iranian Cyber Unit Targeting Israel Exposed
A massive leak has revealed the operations of Iran's elite cyber unit, Charming Kitten, which is linked to the Revolutionary Guards. The leak includes details about the unit's hacking infrastructure and attempts to…
2 articles · Updated November 23, 2025 -
Charming Kitten Leak Exposes Global Cyber Operations and Compromised Systems
The Iranian state-backed group Charming Kitten, also known as APT35, has leaked internal files revealing key personnel, front companies, and thousands of compromised systems across five continents. The leak indicates…
2 articles · Updated December 11, 2025 -
Iranian APT UNK_SmudgedSerpent Targets US Policy Experts with Phishing Attacks
Between June and August 2025, the Iranian-linked APT UNK_SmudgedSerpent conducted targeted phishing campaigns against US academics and foreign policy experts. The group employed techniques such as credential theft and…
5 articles · Updated November 10, 2025
Recent Intelligence Reports
- Iranian APT Group Targets Aviation and Software Firms with Updated Tools — Eplaneai · May 26, 2026
- North Korea's Modular Malware Strategy Hides Attribution, Defies Takedowns — Gbhackers · April 6, 2026
- Conflict sparks surge in Middle East cyber espionage — Securitybrief.Au · March 12, 2026
- New York unveils new cyber regulations for water treatment facilities — Statescoop · March 11, 2026
- APTs and Industrial Cybersecurity in the Wake of the Attack on Iran — Arcweb · March 3, 2026
- AI tapped by Iranian hackers in protest-aimed cyberattacks — Scworld · February 3, 2026
- Siber RedKitten Campaign Related to Iran Attacking Human Rights NGOs, Using AI and ... — Voi.Id · February 2, 2026
- Charming Kitten Leak Exposes Key Personnel, Front Companies, and Thousands of Compromised Systems — Cybersecuritynews · December 11, 2025