ZeroHour

Search: “IRGC”

10 stories in the last 30d

U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks

The U.S. State Department offered up to $10 million for information on Amir Yaryab, an IRGC cyber chief linked to critical infrastructure attacks.

The U.S. State Department's Rewards for Justice program offers up to $10 million for information identifying or locating Amir Yaryab, who allegedly oversees the Cyber Operations Command of Iran's IRGC Cyber-Electronic Command (IRGC-CEC). Officials tie him to units called Shahid Hemmat and Shahid Shushtari conducting cyber and information campaigns against defense, telecommunications, energy, and finance sectors across the US, Europe, and the Middle East, and to groups including CyberAv3ngers and Dadeh Afzar Arman. CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs, including 34 in US water and wastewater facilities, between November 2023 and January 2024.

Cyber Security News · 8d agoPolicy & legal

Florida water agency latest to confirm cyber incident as feds warn of nation

A ransomware gang hit Florida's St. Johns River Water Management District as CISA warned of IRGC-linked CyberAv3ngers attacks on exposed Unitronics water-sector PLCs.

The St. Johns River Water Management District, which oversees Florida drinking-water supply planning, confirmed suspicious activity in its IT environment and said containment measures were implemented; a ransomware gang claimed the attack and shared samples of stolen data. Separately, CISA, FBI, NSA, EPA and Israel's INCD warned that IRGC-affiliated CyberAv3ngers are actively compromising Israeli-made Unitronics Vision Series PLCs in the water sector using default credentials since at least November 22. The group, motivated by opposition to Israel-linked products, defaces controller interfaces and could cause deeper cyber-physical effects. Shadowserver found at least 539 Unitronics PLC instances still exposed online, and CNN reported fewer than 10 US water facilities faced recent attacks.

The Record · 8d agoRansomware in the wild 3 sources

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM

Hacker News ThreatsDay roundup: Defender BTR.sys driver abuse, DoJ charges 17 Mabna Institute members over IRGC-linked intrusions, Grandoreiro sideloading, OpenAI monitoring.

Check Point researchers showed Microsoft's signed Defender Boot-Time Removal driver (BTR.sys) can be repurposed as a universal kernel operation engine to bypass endpoint security without BYOVD. The DoJ charged 17 members of Iran's Mabna Institute, which on behalf of the IRGC stole over 31 TB of academic data from 144 US universities and compromised roughly 8,000 of 100,000 targeted professor accounts; the State Department offered a $10 million reward for five defendants. Separately, Acronis tracked a Grandoreiro campaign abusing DLL sideloading in the Duplicate Files Finder app across Latin America and Spain, while ErrTraffic ClickFix campaigns deliver Cruciferra (BYOVD) and Remus Stealer. OpenAI also previewed Private Safety Processing, a privacy-centric approach to monitoring model misuse without retaining customer content.

The Hacker News · 26d agoThreat actor1

US charges Iranians for sprawling hacking campaign on government agencies, universities

DOJ indicts 17 Iranians tied to Mabna Institute IRGC hacking-for-hire campaign that stole 31TB from universities, agencies, and UN organizations.

The U.S. Justice Department unsealed a 14-count superseding indictment charging 17 people linked to the Mabna Institute, allegedly operating on behalf of the IRGC, in a campaign running since around 2013. The group breached 144 US universities, 42 US companies, 178 foreign universities, 11 foreign companies, and agencies including the Department of Labor, Federal Energy Regulatory Commission, and Hawaii and Indiana state governments, plus UN organizations such as UNICEF, stealing at least 31 terabytes of academic and proprietary data and about 8,000 professor email accounts. The State Department offered a $10 million reward for five individuals including Behzad Mesri, previously indicted for the $6 million HBO extortion; universities spent roughly $20 million on investigation and remediation.

The Record · 8d agoPolicy & legal 2 sources

Nimbus Manticore Expands Toolset With TWOSTROKE

Group-IB found new infrastructure and TWOSTROKE-like malware used by IRGC-linked Nimbus Manticore, indicating expanded Middle East and Europe targeting.

Group-IB reported new Tortoiseshell infrastructure spanning Europe and the Middle East and two previously undocumented tools from IRGC-linked Nimbus Manticore (UNC1549): a reverse SSH tunneling utility connecting to 172.86.98.113 on port 443, and a C++ backdoor masquerading as wtsapi32.dll with three hard-coded C2 servers. The backdoor overlaps with TWOSTROKE and supports file transfer, execution, host information gathering, and persistence. Findings build on Kaspersky's report of the NightLedger backdoor and WebSocket tunnelers BridgeHead and ArcBridge, and suggest expanded targeting beyond the Middle East into Europe.

The Hacker News · 20d agoThreat actor in the wild

US Indicts 17 Iranians Over Years

US unsealed superseding indictment charging 17 Mabna Institute Iranians for IRGC-linked espionage stealing 31TB from universities, companies, and government agencies.

The Justice Department unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute, which conducted hacking campaigns since at least 2013 on behalf of the IRGC and other Iranian clients. The group compromised 144 US and 178 foreign universities, at least 42 US companies, and multiple government agencies, stealing over 31 terabytes of academic data and IP plus employee email inboxes. Hackers breached roughly 8,000 of 100,000 targeted professor accounts across 24 countries, selling stolen research through Megapaper.ir and Gigapaper.ir. Behzad Mesri, tied to the HBO breach and $6 million Bitcoin extortion, is among eight new defendants, and five defendants carry State Department Rewards for Justice bounties up to $10 million.

Security Affairs · 27d agoThreat actor in the wild

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Weekly recap: actively exploited Chrome V8 zero-day, MikroTik RouterOS zero-day chain, Magento StyleSmuggler backdoor, and critical N-able N-central flaws.

Google patched an actively exploited Chrome V8 type confusion zero-day, CVE-2026-85046 (CVSS 8.8), the sixth exploited Chrome zero-day of 2026. CERT Polska warned of the MikroTrick exploit chain (CVE-2026-67276 and CVE-2026-86060, CVSS 9.2) giving unauthenticated full control of MikroTik RouterOS devices via SSH, observed since September 2. Sansec disclosed the StyleSmuggler Magento/Adobe Commerce zero-day used since September 4 to inject a Rust backdoor into online stores, while N-able patched three critical N-central flaws (CVE-2026-86206, CVE-2026-86207, and CVE-2026-86218, CVSS 10.0) with Huntress observing likely exploitation. Elastic and Morphisec also detailed RevStealer, an information stealer spread via game cheats and a fake Claude Desktop app.

The Hacker News · 8d agoExploit / PoC in the wildCVE-2026-85046CVE-2026-86206CVE-2026-86207+7 CVEs

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 12d agoPolicy & legal

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Treasury sanctioned nearly 60 Iran-linked entities, including MOIS-affiliated Mabna Institute hackers behind breaches of U.S. critical infrastructure and millions in crypto theft.

The U.S. Treasury launched Operation Economic Outcast, designating nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, cyber, and digital asset networks. Five sanctioned individuals are members of the Tehran-based Mabna Institute indicted last week; three allegedly breached and exfiltrated data from U.S. energy, defense, healthcare, IT, and financial organizations since late 2023. TRM Labs traced roughly $16.8 million across 30 wallets tied to the members, and the State Department announced a reward of up to $10 million. The action follows Iranian hacking of FBI Director Kash Patel's email and attacks on over 30 U.S. water and wastewater utilities.

The Hacker News · 21d agoPolicy & legal in the wild

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

SecurityWeek weekly roundup covers exploited WordPress Super Forms flaw CVE-2026-14894, a $10M bounty on an Iranian cyber official, InjectEave attacks, and more.

SecurityWeek's weekly roundup aggregates short items across the threat landscape, including Microsoft's report of invisible Unicode tag characters used in financial phishing lures at up to 2.37 million messages per day, and active exploitation of critical WordPress Super Forms plugin flaw CVE-2026-14894 to deploy PHP webshells. Policy items include a $10 million US bounty for IRGC-CEC Cyber Operations Command lead Amir Yaryab, a 16-month prison sentence for ex-AT&T employee Kenneth Carter over SIM swaps with nearly $600,000 in intended losses, and the US arraignment of Russian Sergei Anatolyevich Filimonov over credential harvesting. Technical items include InjectEave electromagnetic side-channel attacks tested on 11 devices, an FBI warning on OAuth consent phishing, and VulnCheck's finding that only 202 of 26,153 Anthropic Project Glasswing findings were fixed.

SecurityWeek · 4d agoIndustry in the wildCVE-2026-148942