logo

Iranian Hackers Use Compromised Cameras for Regional Surveillance

ID: c3cc3508-bcbf-590f-9688-bf4bad985278

STIX ID: report--c3cc3508-bcbf-590f-9688-bf4bad985278

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Iran-linked cyber activity is actively targeting Western organizations and Middle Eastern camera infrastructure: MuddyWater maintained access to US/Canadian targets using new backdoors (Dindoor on Deno and Python-based Fakeset) and Rclone exfiltration; Iran‑linked operators exploited known Hikvision/Dahua vulnerabilities to turn cameras into ISR sensors across multiple countries; and hacktivist proxy Handala claimed large-scale Intune-based remote wipes and theft from Stryker, illustrating a persistent but constrained Iranian cyber ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.