DistantNews
Support us
๐Ÿ‡ฎ๐Ÿ‡ฑ Israel /Conflict & Security

Iran-linked hackers targeted US, Israel and UAE, Palo Alto Networks says

From Jerusalem Post · () English

Summarized by DistantNews. Read the original for the full story.

At a glance

News Documents & data Under investigation
  • An Iran-linked cyber espionage group, Screening Serpens, targeted entities in the US, Israel, and the UAE during recent regional escalations.
  • The group, also known as UNC1549 and Smoke Sandstorm, aligned with Iranian intelligence objectives, deployed new malware variants.
  • Screening Serpens uses sophisticated social engineering tactics, including fake recruitment lures, to compromise targets.

An Iran-nexus cyber espionage group, identified as Screening Serpens, has been implicated in a months-long campaign targeting entities in the United States, Israel, and the United Arab Emirates. Palo Alto Networks' Unit 42 reported that these cyberattacks coincided with recent regional escalations in the Middle East, which began in late February 2026.

The group, also tracked under aliases such as UNC1549 and Smoke Sandstorm, is described as an advanced persistent threat (APT) aligned with Iranian intelligence objectives. During the investigation period from mid-February to April 2026, researchers discovered six new remote access Trojan (RAT) variants, grouped into two new malware families: MiniUpdate and MiniJunk V2. These were deployed in what appeared to be two coordinated waves of cyberattacks, with at least one variant featuring specific timing instructions.

Screening Serpens employs highly tailored social engineering techniques, often impersonating trusted brands and recruitment platforms to target professionals in the technology sector. Attackers have used fake job documents and "Hiring Portal" archives to initiate infection chains. In one instance targeting an Israeli entity, malware was delivered via a file that mimicked an installer for a popular video conferencing platform. Unit 42 noted that the impersonated organization's infrastructure was not breached, indicating the brand was used solely for deception. The group has been active since at least 2022, showing increased technical capabilities and operational resilience, with a primary focus on Middle Eastern targets.

About this summary

Originally published by Jerusalem Post. Summarized and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.