{"id":128941,"date":"2026-05-24T14:45:10","date_gmt":"2026-05-24T14:45:10","guid":{"rendered":"https:\/\/www.europesays.com\/iran\/128941\/"},"modified":"2026-05-24T14:45:10","modified_gmt":"2026-05-24T14:45:10","slug":"palo-alto-networks-iran-linked-hackers-targeted-us-israel-and-uae","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/iran\/128941\/","title":{"rendered":"Palo Alto Networks: Iran-linked hackers targeted US, Israel and UAE"},"content":{"rendered":"<p>An Iran-linked <a href=\"https:\/\/www.jpost.com\/international\/article-896341\" target=\"_blank\" rel=\"nofollow noopener\">cyber<\/a> espionage group targeted entities in the US, Israel, and the United Arab Emirates during a months-long campaign that coincided with the recent regional escalation, Palo Alto Networks\u2019 Unit 42 said in a new report.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The group, known as Screening Serpens, is also tracked under the aliases UNC1549, Smoke Sandstorm, and Iranian Dream Job. Unit 42 described it as an Iran-nexus advanced persistent threat (APT) group aligned with Iranian intelligence objectives.<\/p>\n<p>According to the report, the group targeted entities in the US, Israel, and the UAE, and likely two additional Middle Eastern entities. The research focused on <a href=\"https:\/\/www.jpost.com\/middle-east\/iran-news\/article-896037\" target=\"_blank\" rel=\"nofollow noopener\">cyberattacks<\/a> carried out from mid-February through April 2026.<\/p>\n<p>Unit 42 said the timing of the campaigns closely aligned with the regional conflict that began in the Middle East on February 28, 2026, as well as with <a href=\"https:\/\/www.jpost.com\/tags\/operation-roaring-lion\" target=\"_blank\" rel=\"nofollow noopener\">Operation Roaring Lion<\/a>. During the investigation, researchers identified six new remote access Trojan (RAT) variants that were developed and deployed between February and April 2026.<\/p>\n<p><img alt=\"An illustration of a cyber hacker and the Iranian flag.\" loading=\"lazy\" width=\"822\" height=\"829\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" src=\"https:\/\/www.europesays.com\/iran\/wp-content\/uploads\/2026\/05\/1779633910_969_669519.jpeg\"\/>An illustration of a cyber hacker and the Iranian flag. (credit: PX Media\/Shutterstock)<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The six RAT variants were grouped into two new malware families, called MiniUpdate and MiniJunk V2. Unit 42 said the malware was used in parallel espionage campaigns and that the timing of the deployments indicated two coordinated waves of cyberattacks. At least one variant was compiled and deployed with specific timing instructions.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The most significant development in the group\u2019s latest campaign was its use of a technique called AppDomainManager hijacking, Unit 42 said. The technique manipulates the initialization phase of .NET applications, allowing attackers to disable an application\u2019s security mechanisms through a legitimate configuration file before the application fully starts.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">That left targeted organizations exposed to the multi-functional RATs deployed in the attack, according to the report.<\/p>\n<p>Iranian hacking group uses social engineering<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Screening Serpens primarily targets technology-sector professionals through highly tailored social engineering, often using fake recruitment lures that impersonate trusted brands and hiring platforms, Unit 42 said. In one campaign, attackers used fake job documents and a \u201cHiring Portal\u201d archive to trick technical personnel into launching the infection chain.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">In another campaign that appeared to target an Israeli entity, the malware was delivered via an archive file that impersonated an installer for a popular video conferencing platform. Unit 42 said it found no indication that the impersonated organization\u2019s infrastructure had been breached, adding that the attackers appeared to have used the brand only for impersonation.<\/p>\n<p>Screening Serpens focuses on Middle East targets<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The report said that Screening Serpens has been active since at least 2022 and has demonstrated increased technical capabilities and operational resilience in its recent activities. It has historically focused on regional targets in the Middle East, while more recent campaigns showed expansion into additional arenas.<\/p>\n<p>\u201cAs of April 2026, Screening Serpens activity shows no signs of slowing down and has continued to orchestrate sustained, adaptive global <a href=\"https:\/\/www.jpost.com\/tags\/cyberattack\" target=\"_blank\" rel=\"nofollow noopener\">cyber<\/a> campaigns,\u201d Unit 42 said. The company warned that organizations should expect further attempts in the near term and strengthen their defenses against potential compromise.<\/p>\n","protected":false},"excerpt":{"rendered":"An Iran-linked cyber espionage group targeted entities in the US, Israel, and the United Arab Emirates during a&hellip;\n","protected":false},"author":2,"featured_media":128942,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[33],"tags":[6943,2380,34,37,29126,49,92,709,272,51],"class_list":["post-128941","post","type-post","status-publish","format-standard","has-post-thumbnail","category-israel","tag-cyberattack","tag-cyberwarfare","tag-iran","tag-israel","tag-malware","tag-middle-east","tag-operation-roaring-lion","tag-uae","tag-united-arab-emirates","tag-united-states"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@iran\/116630095481428684","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/posts\/128941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/comments?post=128941"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/posts\/128941\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/media\/128942"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/media?parent=128941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/categories?post=128941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/iran\/wp-json\/wp\/v2\/tags?post=128941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}