Predatory Sparrow: Inside the Cyber Warfare Targeting Iran's Critical Infrastructure
ID: b6d0fb47-b16a-54e0-ab26-3e83f0ff8cb5
STIX ID: report--b6d0fb47-b16a-54e0-ab26-3e83f0ff8cb5
Feed Name: Resources-2
Predatory Sparrow is described as a highly capable, Israel‑linked cyber‑sabotage group that has executed disruptive and destructive campaigns against Iranian critical infrastructure, industrial sites, and financial entities. The report catalogs major incidents (railway paralysis via the Meteor wiper, an Iranian steel plant fire, mass disruption of gas stations, a June 2025 attack on Bank Sepah, and a Nobitex compromise claiming $90M in crypto and leaked source materials), provides malware and script-level analysis (wiper behavior, scheduled tasks, VBS droppers, encrypted configs, event log clearing), maps observed TTPs to ATT&CK, and includes operational details and C2 patterns to support detection and simulation testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
