Tag: Middle East CNI

Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware
News

Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware

A almost two-year-long cyber assault targeting a critical national infrastructure (CNI) in the Middle East has been ascribed to an Iranian state-sponsored threat cell. According to a study by the FortiGuard Incident Response (FGIR) team, the activity, which took place between at least May 2023 and February 2025, involved substantial espionage operations and suspected network prepositioning, a practice frequently employed to preserve persistent access for future strategic gain. The attack shows tradecraft parallels with Lemon Sandstorm (formerly Rubidium), a known Iranian nation-state threat actor that is also monitored as Parisite, Pioneer Kitten, and UNC757, according to the network security firm. According to assessments, it has been active since at least 2017, affecting the wa...