Iran Cyberattacks Against Minnesota Water Systems
Preliminarily attributed to Iran, cyberattacks hit Minnesota water systems as part of a campaign targeting at least seven US states.
A campaign of cyberattacks against water systems in Minnesota and at least six other US states has been preliminarily attributed to Iran, though no real damage has been reported so far. US President Trump publicly disputed the Iranian attribution, blaming Minnesota authorities instead. The incident underscores ongoing nation-state targeting of US water utilities.
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Iran-linked Mirage Kitten targets software engineers with fake LinkedIn recruiter coding tests deploying new NodeRabbit and PollCat RATs.
Kaspersky researchers link the campaign to Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm, Nimbus Manticore), with victims in aviation, aerospace and fintech in Egypt, Ethiopia and Afghanistan. Trojanized npm dependencies (colorized_terminal, pretty-log) bundled in coding-challenge archives launch the Node.js implants across Windows, Linux and macOS. NodeRabbit uses AES-256-GCM-encrypted C2 via Azure, and its third variant persists through a fake GitHub Copilot Helper VS Code extension plus Git post-merge/post-checkout hooks. PollCat is an obfuscated JavaScript RAT that registers with C2 before OTP authentication and inventories tools from 24 security vendors.
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Kaspersky reports Iran-linked Mirage Kitten delivers new NodeRabbit and PollCat malware to fintech and aviation targets via fake LinkedIn coding assessments.
Kaspersky researchers documented two previously undocumented Node.js malware families, NodeRabbit and PollCat, attributed with high confidence to Iran-linked APT group Mirage Kitten. The malware is delivered via fake recruiter personas on LinkedIn offering coding assessments hosted on Amazon S3, with instructions banning AI assistants so AI code-review tools would not flag the trojanized npm packages. NodeRabbit is cross-platform (Windows, Linux, macOS), uses AES-256-GCM-encrypted C2 on Azure, includes sandbox checks, and one variant installs a fake 'GitHub Copilot Helper' VS Code extension plus Git hook persistence. Victims identified so far are in fintech and aviation organizations across Egypt, Ethiopia, and Afghanistan.
Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Group-IB found Iran-linked Tortoiseshell expanding command-and-control infrastructure into the UK, Belgium, Saudi Arabia and the UAE with new malware tooling.
Group-IB researchers identified new Tortoiseshell command-and-control infrastructure, including servers named 'uk1' and 'uk2' hosted on UK IP addresses, plus systems in Belgium, Saudi Arabia and the UAE. The Iran-linked espionage group, active since at least 2018 and previously tied to the Islamic Revolutionary Guard Corps, has historically targeted defense, aerospace, technology and military organizations in the Middle East and the United States. Researchers also uncovered new malware samples, including a backdoor resembling TwoStroke that enables command execution, file theft and system reconnaissance, and a tool establishing reverse SSH tunnels to attacker-controlled servers. Group-IB assesses that the group is expanding both its geographic reach and its capabilities and ranks it among the most active Iranian APTs of 2026.
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
Iran-linked hackers hit water utilities in New Jersey and Alabama, bringing confirmed US water-infrastructure attacks to at least 12 states.
Iran-linked hackers attacked the Cape May Sewer Department and Woodbine Water Department in New Jersey and the Childersburg Water, Sewer and Gas system in Alabama on July 27, bringing confirmed US water-sector attacks to at least 12 states since late July. The intrusions targeted internet-exposed industrial control systems, including Rockwell Automation PLCs, with roughly 12 hours of impact in New Jersey and no impact on water quality or service. The FBI confirmed seven affected states by July 30, and CISA has urged utilities to remove PLCs from direct internet exposure. New York announced more than $9 million in grants to strengthen water-sector cybersecurity.
Iranian spies hit Windows machines with Chosen Brick data-stealing malware
FBI, UK NCSC, and Dutch AIVD warn Iranian intelligence uses Chosen Brick spyware against dissidents, stealing contacts, emails, and messaging data.
A joint advisory from the FBI, UK NCSC, and Dutch AIVD says Iranian state cyber actors have used the Chosen Brick Windows malware since at least 2025 to surveil dissidents, activists, and journalists. Attacks begin with heavily researched WhatsApp and Telegram messages impersonating trusted contacts, tricking victims into opening fake installers resembling Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The malware persists via the HKCU Run registry key, adds Microsoft Defender exclusions, uses victim-specific Telegram bots for C2, captures screen and audio, steals emails and Telegram/WhatsApp data, and can wipe systems.
U.S. agencies say Iranian hackers tried to pass ‘non-public’ Trump campaign docs to Biden’s campaign
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic's 154-page report details Generative Threat Groups, including APT29-linked GTG-20006 and ShinyHunters affiliates, using Claude for reconnaissance, exploitation, and data theft.
Anthropic reports that between December 2025 and August 2026 state-sponsored hackers, criminals, spyware vendors, and propaganda operators used its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance. Notable clusters include GTG-50014, a ShinyHunters affiliate that scanned 1.8 million Android APKs for secrets via 10 AWS EC2 workers, GTG-10007, a Chinese-speaking group targeting roughly 50 organizations, and GTG-50029, a lone French-speaking actor exploiting a previously undocumented WordPress re-installation race condition. The report describes multi-agent frameworks autonomously executing reconnaissance, exploitation, and exfiltration against multiple victims, and influence operations that were disrupted before building authentic audiences.
Iranian APTs increased activity against US industries in late spring, researchers say
Nozomi Networks recorded 28 Iran-linked attacks on US customers in May-June, up 133%, mostly hitting transportation and manufacturing.
Nozomi Networks telemetry showed 28 Iran-linked attacks against customers in May and June versus 12 in the prior two months, a 133% increase focused on transportation and manufacturing. MuddyWater was the most active group, targeting at least five US companies, followed by APT33 with at least three; OilRig, CyberAv3ngers, FoxKitten and Homeland Justice were also active. In a separate report, Morphisec said Fox Kitten is recruiting ransomware affiliates with an 80% share of proceeds for attacks against Iran's adversaries, including the US and Israel. The activity comes amid heightened concerns over Iranian cyber retaliation after US strikes on Iranian nuclear facilities.
US sanctions Iranian cyber actors as UK discloses power plant attack
US Treasury sanctioned six Iranian MOIS-linked hackers for breaching US agency and UN email accounts as the UK disclosed a four-day power plant shutdown.
The US Treasury sanctioned at least six Iranian nationals tied to a hacking team inside Iran's Ministry of Intelligence and Security (MOIS) active since 2023; four were indicted last week for breaching employee email accounts at the Department of Labor, the Federal Energy Regulatory Commission and United Nations organizations. Treasury said the group compromised energy, defense, healthcare, IT and financial sector targets, multiple US government offices in summer 2024, and stole cryptocurrency for personal gain. Separately, Iranian actors reportedly shut down a small British power plant for four days without grid impact, days after FBI and NSA warned of hackers targeting programmable logic controllers in energy, water and agriculture.
US Indicts 17 Iranians Over Years
US unsealed superseding indictment charging 17 Mabna Institute Iranians for IRGC-linked espionage stealing 31TB from universities, companies, and government agencies.
The Justice Department unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute, which conducted hacking campaigns since at least 2013 on behalf of the IRGC and other Iranian clients. The group compromised 144 US and 178 foreign universities, at least 42 US companies, and multiple government agencies, stealing over 31 terabytes of academic data and IP plus employee email inboxes. Hackers breached roughly 8,000 of 100,000 targeted professor accounts across 24 countries, selling stolen research through Megapaper.ir and Gigapaper.ir. Behzad Mesri, tied to the HBO breach and $6 million Bitcoin extortion, is among eight new defendants, and five defendants carry State Department Rewards for Justice bounties up to $10 million.
Pro-Palestinian operation claims dozens of data breaches against Israeli firms
Hacktivist group Cyber Toufan claims 60 data breaches of Israeli and allied firms, wiping systems and erasing backups; Check Point links it to Iran.
The pro-Palestinian group Cyber Toufan said it released stolen data from 60 Israeli and foreign firms, including SpaceX, Toyota and IKEA, as part of a month-long leak operation launched in late November. Researchers at Check Point and SOC Radar assess the leaks are genuine, likely stemming partly from a major attack on Israeli hosting company Signature-IT, and attribute the group to Iran; researcher Kevin Beaumont said roughly a third of victims remain offline weeks later with backups erased. Google blocked the group's Telegram leak channel, while about 10 Iranian-backed hacking groups are assessed to be attacking Israel in the ongoing cyberwar.
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.
The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
Joint advisory details Iranian spear-phishing campaign deploying CHOSEN BRICK spyware to surveil dissidents, activists, and journalists across UK, US, Netherlands.
The NCSC (part of GCHQ), FBI, and AIVD jointly warned that Iranian state actors impersonate trusted contacts on WhatsApp and Telegram to deploy the CHOSEN BRICK spyware against dissidents, activists, and journalists worldwide. The Windows-only malware is persistent across reboots and collects contacts, emails, social media messages, screen captures, and microphone audio. Stolen personal details of some victims have been published on pro-Iranian leak sites. The FBI published complementary technical analysis, and the NCSC offers free cyber defence services for high-risk individuals.
CISA confirms hackers targeted over 100 US water systems during July
CISA says hackers targeted over 100 US water systems in July amid suspected Iran-backed attacks on critical water infrastructure.
CISA confirmed that hackers targeted more than 100 US water systems during July. The federal agency's warning comes amid a wave of suspected Iran-backed cyberattacks against critical water infrastructure across the United States. The available text does not specify intrusion methods, compromised utilities by name, or data impact.