logo

The LA Metro Attack Wasn’t Hacktivism. It Was a State Operation With a Costume On.

ID: 4010694b-887c-533f-87c9-f0372e4b16c5

STIX ID: report--4010694b-887c-533f-87c9-f0372e4b16c5

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Pierluigi Paganini

...
...

The report links the Ababil of Minab campaign that wiped hundreds of terabytes and exfiltrated data from LA Metro and other victims to Iran’s MOIS/Black Shadow, describing hands‑on and scripted destructive techniques, bespoke tooling (wipers, FileFiend, a Flask-based exfiltration server), staging infrastructure and indicators used for attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.