Minacce e avversari · DDoS
Gruppi legati all'Iran e attori pro‑Iran hanno intensificato operazioni distruttive e di estorsione informatica. TeamPCP ha lanciato un self‑propagating worm e un wiper che cancella macchine con timezone o locale Iran, e ha compromesso Trivy per distribuire backdoor credential‑stealing.
18 fonti · 24 mar
The Record from Recorded Future
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.
originaleArs Technica Security
Self-propagating malware poisons open source software and wipes Iran-based machines
Development houses: It's time to check your networks for infections.
originaleSecurityWeek
Stryker Says Malicious File Found During Probe Into Iran-Linked Attack
The FBI has published an alert describing the malware used by Iranian government hackers.
originalePart of the PlainSec briefing for 2026-03-24
Every edition of this story: Operazioni Cyber Legate all'Iran Aumentano: Wiper e Ransomware