Threats & Adversaries · DDoS
Iran-aligned state and proxy actors have stepped up DDoS, data-wiping and deep intrusion operations after recent US-Israeli strikes. Claims include mass data destruction and attacks on government and healthcare systems. Security vendors warn reconnaissance and pre-positioned access raise risk of sustained disruption to energy and supply chains.
18 sources · Mar 24
The Record from Recorded Future
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.
originalArs Technica Security
Self-propagating malware poisons open source software and wipes Iran-based machines
Development houses: It's time to check your networks for infections.
originalSecurityWeek
Stryker Says Malicious File Found During Probe Into Iran-Linked Attack
The FBI has published an alert describing the malware used by Iranian government hackers.
originalPart of the PlainSec briefing for 2026-03-20
Every edition of this story: Iran Deploys Cyber Chaos Campaign to Pressure Rivals