logo

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

ID: 778651c8-1825-5821-bb6f-ce62b97c2bbc

STIX ID: report--778651c8-1825-5821-bb6f-ce62b97c2bbc

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Unit 42

...
...

Unit 42 documents a series of coordinated cyberespionage campaigns (Feb–Apr 2026) by the Iran-linked APT "Screening Serpens" that deployed two RAT families (MiniUpdate and MiniJunk V2) against targets in the U.S., Israel, the UAE and other Middle Eastern entities; the report details tailored social-engineering lures, DLL sideloading, advanced .NET AppDomainManager hijacking to disable ETW and strong-name checks, persistence mechanisms, C2 infrastructure, and provides IOCs and defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.