Iran-Related Cyber Campaigns Spike with Wipers and Ransomware
Iran-linked and aligned actors have stepped up destructive intrusions, supply-chain compromises, and DDoS operations. Reported incidents include Pay2Key encrypting a US healthcare environment with no confirmed exfiltration. Researchers also link a Stryker disruption to Handala activity abusing Intune and a worm-driven compromise of the Trivy scanner that poisoned npm packages.
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.