Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization
ID: e51632f9-f166-54f7-ad22-58c700d1a97d
STIX ID: report--e51632f9-f166-54f7-ad22-58c700d1a97d
Feed Name: Palo Alto Networks Unit 42
This report analyzes the evolution of Iranian-aligned cyber actors from destructive, custom wiper malware to large-scale identity and management-plane abuse (MDM/RMM), describing historical campaigns, notable malware families and groups (e.g., Shamoon, Agonizing Serpens, Void Manticore), and warning that compromise of privileged administrative identities can enable mass remote-wipe operations that bypass traditional EDR—recommending identity-centric defenses such as Zero Trust, PIM/JIT, strict conditional access, and air-gapped backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
