Threats Tagged 'iran'
View all threats tagged with 'iran'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'iran'
Click on any threat for detailed analysis and mitigation recommendations
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig. Join the discussion | AlienVault OTX General | 07/06/2026, 14:02:13 UTC Added: 07/07/2026, 14:14:38 UTC |
TAG-182, an Iran-nexus threat cluster, is conducting surveillance operations targeting Iranian citizens both domestically and abroad using MarkiRAT malware. The group distributes fake Android applications masquerading as VPN services and media players through social media platforms, particularly Instagram. Following Iran's partial internet restoration in May 2026 after an 88-day shutdown, these surveillance activities have intensified as Iranian security apparatus seeks to monitor perceived dissidents and anti-government activists. MarkiRAT samples demonstrate tradecraft overlaps with previously documented Ferocious Kitten operations, including use of Background Intelligent Transfer Service (BITS). The group operates infrastructure across multiple autonomous systems, utilizing domains with naming conventions mimicking legitimate services like Microsoft, Google, and Facebook. Join the discussion | AlienVault OTX General | 07/01/2026, 16:58:02 UTC Added: 07/02/2026, 07:06:43 UTC |
Iranian state-sponsored threat group Seedworm conducted a widespread espionage campaign in early 2026, compromising at least nine organizations across nine countries on four continents. Victims included a major South Korean electronics manufacturer, government agencies, an international airport in the Middle East, Southeast Asian industrial manufacturers, a Latin American financial services provider, and educational institutions. The attackers utilized DLL sideloading techniques with legitimately signed Fortemedia and SentinelOne binaries to execute malicious payloads, deployed Node.js-based implants for orchestration, and employed multiple PowerShell scripts for reconnaissance, credential theft, and privilege escalation. Data exfiltration was conducted through public file-transfer service sendit.sh to blend malicious traffic with legitimate cloud services. The campaign demonstrates Seedworm's evolved tradecraft and expanded targeting beyond traditional Middle Eastern focus areas. Join the discussion | AlienVault OTX General | 05/12/2026, 13:58:56 UTC Added: 05/12/2026, 16:51:32 UTC |
A significant joint offensive by the US and Israel has triggered a multi-vector retaliatory campaign from Iran, leading to an escalation in cyberattacks. Iran's limited internet connectivity is likely hindering state-aligned threat actors' ability to coordinate sophisticated attacks. Hacktivist groups are targeting perceived adversaries, while other nation-state actors may exploit the situation. Observed activities include phishing campaigns, DDoS attacks, data exfiltration, and wiper attacks. Multiple Iranian state-aligned personas and collectives have claimed responsibility for various disruptive operations. Pro-Russian hacktivist groups have also been active, targeting Israeli systems and infrastructure. The situation remains fluid, and organizations are advised to implement multi-layered defenses and focus on foundational security hygiene. Join the discussion | AlienVault OTX General | 03/03/2026, 06:39:44 UTC Added: 03/03/2026, 17:02:26 UTC |
RedKitten is a newly identified campaign targeting Iranian interests, first observed in January 2026. The malware uses GitHub and Google Drive for configuration and payload retrieval, and Telegram for command and control. It appears to exploit the Dey 1404 Protests in Iran, targeting organizations documenting human rights abuses. The threat actor rapidly built this campaign using AI tools, as evidenced by traces of LLM-assisted development. While attribution is not definitive, the activity aligns with Iranian state-sponsored attackers. The malware, dubbed SloppyMIO, can fetch modules, execute commands, collect files, and deploy additional malware with persistence. Join the discussion | AlienVault OTX General | 01/29/2026, 21:45:57 UTC Added: 01/30/2026, 08:12:47 UTC |
MuddyWater, an Iran-aligned cyberespionage group, has been targeting critical infrastructure in Israel and Egypt with custom malware and improved tactics. The campaign uses previously undocumented tools like the Fooder loader and MuddyViper backdoor to enhance defense evasion and persistence. Fooder masquerades as a Snake game and uses game-inspired techniques to hinder analysis. MuddyViper enables system information collection, file manipulation, and credential theft. The group also employs browser-data stealers and reverse tunneling tools. This campaign demonstrates MuddyWater's evolution towards more sophisticated and refined approaches, though traces of operational immaturity remain. The group continues to pose a significant threat, particularly to government, military, telecommunications, and critical infrastructure sectors in the Middle East. Join the discussion | AlienVault OTX General | 01/03/2026, 11:05:58 UTC Added: 01/05/2026, 11:18:20 UTC |
ESET researchers have identified a new cyberespionage campaign by the Iran-aligned MuddyWater group targeting organizations in Israel and Egypt. The group uses custom malware tools, including a Fooder loader and the MuddyViper backdoor, employing advanced techniques such as CNG cryptography and reflective loading. The campaign focuses on critical infrastructure sectors and uses spearphishing emails with links to remote monitoring and management software to deliver its payloads. MuddyWater's toolset includes browser data stealers, credential stealers, and reverse tunneling tools, indicating enhanced stealth and credential harvesting capabilities. Join the discussion | AlienVault OTX General | 12/02/2025, 14:44:59 UTC Added: 12/03/2025, 18:13:50 UTC |
An Iranian-aligned spear-phishing campaign masquerading as Omani Ministry of Foreign Affairs communications targeted global government entities. The operation used compromised mailboxes to distribute malicious Word documents containing VBA macros. When executed, these macros decoded and deployed a payload named sysProcUpdate, which gathered system metadata and attempted to beacon to a command and control server. The campaign showed sophisticated techniques including anti-analysis measures, persistence mechanisms, and regional targeting across multiple countries. Evidence suggests this was part of a broader espionage effort by the Homeland Justice group associated with Iran's Ministry of Intelligence and Security, coinciding with heightened geopolitical tensions. Join the discussion | AlienVault OTX General | 09/03/2025, 17:31:16 UTC Added: 09/03/2025, 20:02:47 UTC |
0 MuddyWater, an Iranian cyber espionage group linked to Iran's Ministry of Intelligence and Security, is deploying DCHSpy, an Android surveillanceware, amid the Israel-Iran conflict. DCHSpy is distributed via malicious VPN apps promoted on Telegram channels and is capable of extensive data collection including WhatsApp data, contacts, SMS, files, location, call logs, audio recordings, and photos. Recent variants have enhanced capabilities for exfiltrating data from specific files and WhatsApp. The malware's targeting appears to leverage StarLink-related lures, exploiting Iran's internet outages. DCHSpy shares infrastructure with SandStrike, another Android malware targeting Bahá’í practitioners. This threat poses significant espionage risks to individuals in conflict zones and those using Android devices in targeted regions. Join the discussion | AlienVault OTX General | 08/21/2025, 16:16:28 UTC Added: 08/21/2025, 19:32:47 UTC |
The Iranian threat group Educated Manticore, associated with the Islamic Revolutionary Guard Corps, has launched spear-phishing campaigns targeting Israeli journalists, cyber security experts and computer science professors. The attackers posed as fictitious assistants to technology executives or researchers, directing victims to fake Gmail login pages or Google Meet invitations. This allowed them to intercept passwords and 2FA codes, gaining unauthorized access to victims' accounts. The group used a custom phishing kit implemented as a Single Page Application built with React, supporting various Google authentication flows and enabling 2FA relay attacks. The infrastructure relied on over 130 unique domains resolving to multiple IP addresses. Despite increased exposure, Educated Manticore continues to pose a persistent threat, particularly to individuals in Israel during the Iran-Israel conflict escalation. Join the discussion | AlienVault OTX General | 06/26/2025, 21:01:42 UTC Added: 06/26/2025, 21:04:55 UTC |
Showing 1 to 10 of 12 results