A almost two-year-long cyber assault targeting a critical national infrastructure (CNI) in the Middle East has been ascribed to an Iranian state-sponsored threat cell.
According to a study by the FortiGuard Incident Response (FGIR) team, the activity, which took place between at least May 2023 and February 2025, involved substantial espionage operations and suspected network prepositioning, a practice frequently employed to preserve persistent access for future strategic gain.
The attack shows tradecraft parallels with Lemon Sandstorm (formerly Rubidium), a known Iranian nation-state threat actor that is also monitored as Parisite, Pioneer Kitten, and UNC757, according to the network security firm.
According to assessments, it has been active since at least 2017, affecting the water, electric, oil and gas, and aerospace industries in the US, the Middle East, Europe, and Australia. Dragos, an industrial cybersecurity firm read more about Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
