logo

New Screening Serpens Cyberattacks Target Global Technology Professionals

ID: 6c7f36f2-66af-579b-9cf7-a0643f5cadcc

STIX ID: report--6c7f36f2-66af-579b-9cf7-a0643f5cadcc

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ddos

...
...

Unit 42 reports a mid-February–April 2026 Iran-linked APT campaign dubbed Screening Serpens (also tracked as UNC1549/Smoke Sandstorm) targeting organizations in the US, Israel, the UAE and other Middle Eastern entities; operators use highly tailored recruitment lures and spoofed meeting invites to deliver malware that abuses DLL sideloading and .NET AppDomain Manager hijacking to install six newly observed RAT variants (grouped into two malware families) for persistent access and data exfiltration, and defenders are advised to tune EDR to detect these execution behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.