A Cyber-Psychological Operation: Iran-Linked Attackers Target Warning Systems
ID: 7b51ee7a-7f57-5688-b82c-b7d5f5a5fd7a
STIX ID: report--7b51ee7a-7f57-5688-b82c-b7d5f5a5fd7a
Feed Name: Claroty Team82
Threat Score
This report documents Iran-affiliated groups (CyberAv3ngers and Handala) targeting legacy Barix AoIP devices and PA/siren infrastructure—exploiting CVE-2024-41700 and supply-chain/management access—to hijack or silence emergency alerts as a form of psychological warfare; it includes forensic log and video analysis, mapped attack phases, links to prior campaigns and custom malware (IOCONTROL), and highlights the risk posed by exposed, manually-patched legacy devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
