Iranian Cyber Ops Maintain US Network Footholds, Target Cameras for Regional Surveillance
ID: 56fede14-4f83-5ee0-8fca-fe88a2edd8a1
STIX ID: report--56fede14-4f83-5ee0-8fca-fe88a2edd8a1
Feed Name: cybersecurityNews.com
Iran-linked actors—primarily the MuddyWater APT and affiliated proxies—conducted sustained espionage and battlefield intelligence operations in early 2026, maintaining persistent access to US and Canadian organizations across banking, aviation, defense supply chains, and non-profits while scanning and exploiting Hikvision and Dahua surveillance cameras across multiple Middle Eastern countries; the report documents use of multiple malware families (Dindoor, Fakeset, Stagecomp, Darkcomp), exploitation of known camera CVEs, certificate-signed malware, Rclone-based exfiltration indicators, and a claimed destructive Handala wiper attack on Stryker with ~50 TB exfiltrated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
