logo

'Lemon Sandstorm' Underscores Risks to Middle East Infrastructure

ID: 87dd338f-1d60-5afe-bee4-0d66e9ae1674

STIX ID: report--87dd338f-1d60-5afe-bee4-0d66e9ae1674

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-05-08

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

An Iran-backed APT dubbed "Lemon Sandstorm" infiltrated a Middle Eastern critical national infrastructure provider over at least two years using stolen VPN credentials, Exchange web shells, and five custom tools to establish long-term persistence and attempt lateral movement toward operational technology (OT) systems; strong network segmentation prevented OT compromise and little data exfiltration was observed. Fortinet assisted remediation and the report emphasizes hardening measures such as multifactor authentication, rapid patching, network segmentation, and regular incident-response exercises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.