Tag: iran
-
InfoguardIntelligence-Report Cyberrisiko Iran
Staatliche Akteure etablieren sich langfristig in Netzen, OT- und Edge-Systeme gewinnen als Angriffsziele an Bedeutung und KI beschleunigt Angriffsketten. Der Iran ist zudem gegenwärtig eine akute Bedrohung, die häufig unter dem Radar fliegt. Das sind die zentralen Erkenntnisse des aktuellen Infoguard-Threat-Reports Q3/26. Unternehmen müssen angesichts dieser Lage ihre Cyberresilienz stärken, um exponierte Systeme frühzeitig zu…
-
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.”HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, First seen on thehackernews.com Jump to article:…
-
Congress eyes new support for Cyber Command after recent suicide deaths
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela. First seen on therecord.media Jump to article: therecord.media/congress-eyes-support-for-cyber-command-suicide-deaths
-
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/aws-middle-east-outage-permanent-data-loss-bahrain-uae/
-
Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs
Iranian state-linked attackers are using fake MRI scans and software lures to deploy CHOSEN BRICK spyware on Windows PCs. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-chosen-brick-spyware-windows/
-
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They’re all vulnerable to Iranian cyberattacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
-
US Boarded 2 Oil Tankers to Investigate Cyberattacks
Foreign Tankers Were Bound for Texas When Networks Were Compromised. The Coast Guard and FBI boarded two foreign oil tankers bound toward Texas after signs their networks were compromised, inspecting IT and operational systems as authorities examined possible links to the broader U.S.-Iran conflict. There are no reports of operational disruptions, the FBI said. First…
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
-
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/
-
UK, US and Netherlands warn of Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted…
-
Iranian Hackers Dodging Corporate Defenses to Reach Critics
Joint Advisory Details Chosen Brick Spyware Used Against Iran’s Critics Abroad. Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture screens, record audio and steal messages, according to a joint advisory from British, U.S. and Dutch intelligence agencies. First seen on…
-
UK, US and Netherlands warn over Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate…
-
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.” First seen on therecord.media Jump to article: therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure
-
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.” First seen on therecord.media Jump to article: therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure
-
Iran, Yemeni Cell Used Claude in Developing Weapons, Threats: Anthropic
An Iranian-sponsored threat group and a likely Houthi engineering cell used Anthropic’s Claude and other AI tools to gather information on U.S. naval operations and to develop software for missile systems. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/iran-yemeni-cell-used-claude-in-developing-weapons-threats-anthropic/
-
The Cyber Express Weekly Roundup: Iranian Bounty, Airline Data Leak, and AI-Model Prompt Injection
This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-iran-bounty-airline-leak/
-
U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Amir Yaryab
The U.S. Department of State’s Rewards for Justice (RFJ) program has announced a reward of up to $10 million for information leading to the identification or location of Amir Yaryab, a senior official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). This reward applies to information about individuals acting under the direction of, or…
-
ISMG Editors: Cybersecurity’s Paper Problem Isn’t Dead
Also: AI Attacks Exploit Security Debt, Iran Targets US Critical Infrastructure. In this week’s panel, ISMG editors discussed sensitive mental health records left to rot in abandoned buildings, how mounting security debt could leave firms exposed to AI-powered attacks and how the escalating U.S.-Iran conflict is raising new concerns about attacks on critical infrastructure. First…
-
US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure
Amir Yaryab is the leader of the IRGC’s cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him. First seen on therecord.media Jump to article: therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
-
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were…

