Tag: iran
-
Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn and other job-search platforms, weaponized Node.js projects, and cloud-hosted ZIP archives to gain covert access to developer endpoints across Windows, Linux, and macOS.…
-
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia. First seen on therecord.media Jump to article: therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware
-
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.Russian cybersecurity company Kaspersky is tracking the First seen…
-
Iran Cyber Risk Climbs as US Resumes Strikes
Kinetic Escalation Has Preceded Every Wave of US Utility Intrusions. U.S. forces struck two Iranian rocket launchers near the Strait of Hormuz on Sunday, ending a monthlong lull in a conflict where every kinetic escalation has been followed by federal warnings about Iranian-linked probing of water and energy control systems. First seen on govinfosecurity.com Jump…
-
Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in reporting to Iran-affiliated hackers, the UK government and National Cyber Security Centre (NCSC) have not formally attributed the incident to Iran or any named threat group. The event became…
-
UK’s small power plants face higher cyber risk into 2030s despite Iran-linked hack
Decision not to improve resilience sooner described as ‘unacceptable gamble with our national security’Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which is understood to have shut…
-
UK’s small power plants face continued cyber risk after Iran-linked hack
Government measures to improve resilience are not due until 2030 and July’s hack has not altered this timeline<br><br> Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which…
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
CISA confirms hackers targeted over 100 US water systems during July
The federal cyber agency’s warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july/
-
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead.…
-
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have legitimate uses on Windows systems, making malicious activity harder to distinguish from normal software behavior. According to Cybersecurity News, Iran-linked operators are abusing the legitimate Deno JavaScript…
-
Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Researchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group. First seen on therecord.media Jump to article: therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east
-
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The…
-
UK Government Reticent Over Power Plant Hack
Government Tight Lipped Over Possible Iranian Hack, Experts Complain. Operational technology security leaders are calling on the British government to release technical details of a cyberattack last month that took a small power plant offline for four days. So far, the government’s public statements have been very limited, and hopefully, we’ll find out more soon.…
-
Iran-Linked Hackers Blamed for UK Energy Cyberattack
A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds. The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It…
-
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers.”We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical…
-
Suspected Iran-Linked Cyberattack Shuts UK Power Generator for Four Days
A suspected Iran-linked cyberattack reportedly forced a small UK power generator offline for four days, raising concerns about infrastructure resilience. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-iran-linked-hackers-uk-power-plant-cyberattack-emea/
-
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/us-sanctions-mabna-institute/
-
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom. First seen on therecord.media Jump to article: therecord.media/iran-cyberattacks-us-uk
-
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/
-
UK power plant shutdown highlights CNI cyber challenges
An alleged Iranian attack on a small reserve ‘peaker’ power plant went largely unnoticed despite causing four days of downtime. Cyber experts say the incident raises serious questions about CNI resilience. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649386/UK-power-plant-shutdown-highlights-CNI-cyber-challenges
-
US Charges 17 Iranian Hackers Over Theft of 31.5TB of Academic Data
US prosecutors charge 17 Iranians hackers over an alleged campaign that stole 31.5TB of research and targeted universities, companies and government agencies worldwide. First seen on hackread.com Jump to article: hackread.com/us-charges-iranian-hackers-theft-31b-academic-data/
-
Suspected Iran-linked attack knocked UK power plant offline for days
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/uk-power-plant-cyberattack/
-
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cni-iranian-attack-shuts-uk-power/
-
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cni-iranian-attack-shuts-uk-power/
-
Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack
A cyberattack linked to Iranian threat actors forced a British power plant offline for four consecutive days in July, reportedly marking the first successful cyber incident to disrupt a UK energy-generation facility completely. This incident, first reported by The Telegraph, affected a small-scale electricity generator rather than a major power station. The UK government emphasized…
-
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy…
-
What we know so far about the hacking campaign against US water systems
Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/what-we-know-so-far-about-the-hacking-campaign-against-us-water-systems/828374/
-
US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute,…
-
US charges 17 Iranian hackers over 31-terabyte academic data theft
The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/us-iranian-hackers-mabna-institute-charged/

