Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • US Puts $10 Million Bounty on Alleged Iranian Cyber Chief Samiksha Jain
    The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers
     

US Puts $10 Million Bounty on Alleged Iranian Cyber Chief

7 de Setembro de 2026, 02:51

$10 Million Reward for Amir Yaryab

The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN). U.S. officials accuse these groups of using malware and conducting cyber and cyber-enabled information operations against civilian infrastructure worldwide.

$10 Million Reward for Amir Yaryab

The $10 million reward for Amir Yaryab seeks information leading to his identification or location. The offer applies to individuals acting at the direction or under the control of a foreign government who participate in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. [caption id="attachment_113961" align="aligncenter" width="600"]$10 million reward for Amir Yaryab Image Source: https://rewardsforjustice.net/[/caption] Yaryab is also accused of directing Shahid Hemmat and Shahid Shushtari, two groups linked to cyberattacks against U.S. organizations. The sectors allegedly targeted include defense, news, shipping, travel, energy, financial services and telecommunications. The six Iranian officials named in the advisory are linked to Iran's Islamic Revolutionary Guard Corps and its Cyber-Electronic Command.

Iranian Cyberattacks Target PLCs

The allegations also involve attacks against programmable logic controllers (PLCs), highlighting concerns around Iranian cyberattacks targeting industrial systems rather than focusing only on data theft. U.S. officials said Iranian-linked hackers compromised industrial control systems, specifically targeting the Vision series of PLCs manufactured by Israel-based Unitronics. These devices are used across water and wastewater, energy, food and beverage, manufacturing and healthcare sectors. The attackers exploited default credentials on the devices and left anti-Israel messages. Some of the compromises reportedly rendered the PLCs inoperative. The CyberAv3ngers group, which is linked to the IRGC-CEC, claimed responsibility for attacks against Unitronics Vision PLCs in October 2023. Beginning in November 2023, the group compromised default credentials in PLCs across the United States and left messages on the devices' digital screens.

CyberAv3ngers Attacks Critical Infrastructure

CyberAv3ngers has also claimed responsibility for attacks affecting other infrastructure. In October 2023, the group claimed it had breached ORPAK Systems, a provider of gas station solutions in Israel. The group said it had obtained the company's database and intended to publish it through its Telegram channel. The attack was reported to have disconnected 200 gasoline pumps from the system in the occupied Palestinian territories. In December 2023, CyberAv3ngers also claimed to possess and sell 1TB of data allegedly linked to Israel's electricity infrastructure. The group advertised the dataset for 5 Bitcoin, with an initial 100GB portion also offered at the same price.

U.S. Agencies Warn of PLC Cyberattacks

Concerns over critical infrastructure attacks involving PLCs continued into 2026. A joint advisory issued on April 7 by the FBI, CISA, NSA and other agencies warned that Iran-linked threat actors were actively exploiting internet-facing PLCs. The advisory said several organizations had experienced operational disruptions and financial losses after attackers interfered with industrial processes. The developments come amid broader U.S. actions against Iranian-linked cyber activity. The Justice Department accused Iran-connected hackers of breaching employee email accounts associated with the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. The Treasury Department also sanctioned Iranian nationals over cyberattacks targeting critical infrastructure. The State Department's reward offer places Amir Yaryab and the alleged activities of IRGC-CEC-linked groups at the center of the U.S. effort to identify individuals responsible for malicious cyber activity targeting critical infrastructure.
  • ✇Firewall Daily – The Cyber Express
  • CISA, FBI Urge Clearer Communication During Major Outages Samiksha Jain
    The CISA and FBI, along with cybersecurity agencies from Australia, Canada, New Zealand and the U.K., have released new guidance on outage communications for service providers dealing with major IT and OT outages. The guide calls for prompt, factual and audience-specific communication during disruptions caused by malicious cyber activity or non-malicious events. Titled “Communicating Under Pressure: Best Practices for Service Providers,” the guidance says effective communication is critical to
     

CISA, FBI Urge Clearer Communication During Major Outages

3 de Setembro de 2026, 02:37

outage communications

The CISA and FBI, along with cybersecurity agencies from Australia, Canada, New Zealand and the U.K., have released new guidance on outage communications for service providers dealing with major IT and OT outages. The guide calls for prompt, factual and audience-specific communication during disruptions caused by malicious cyber activity or non-malicious events.

Titled “Communicating Under Pressure: Best Practices for Service Providers,” the guidance says effective communication is critical to limiting operational impact when IT and OT outages affect customers, network defenders, critical infrastructure owners and operators, and the public. It recommends that organizations clearly communicate what is known, what remains unknown and what is still under investigation, while providing frequent updates as circumstances change.

Outage Communications Should Start With Facts

The agencies recommend that service providers establish an outage communications plan before an incident occurs. The plan should define incident thresholds, escalation paths, target audiences and procedures for status pages, customer and partner notices, and regulatory communications. Organizations are also advised to establish cross-functional incident teams involving engineering and operations, communications, legal, risk and compliance, and customer support.

The guidance calls for clearly defined roles, including an incident lead, communications lead and spokesperson. It also recommends parallel workstreams so technical teams can focus on diagnosing and remediating the root cause while communications teams manage external messaging and leadership handles strategy and regulatory requirements.

For organizations responding to cyber incidents, the guidance places particular emphasis on balancing transparency with operational security. If malicious activity is suspected or confirmed, external communications should not compromise investigations, containment efforts or other response activities. Organizations are also advised against making premature conclusions when the root cause remains under investigation.

Service Providers Urged to Tailor Messages

The guidance recommends segmenting communications for technical teams, executives and the public. Audiences can include enterprise IT teams and security operations centers, employees and customers, government partners and regulators, critical infrastructure owners and operators, as well as the media and general public.

During an outage, organizations should lead with a concise summary covering affected systems, user impact, scope and the known cause without speculation. The agencies also advise against vague descriptions such as “service degradation” and recommend messaging that can be understood quickly during high-pressure situations.

Transparency is another central principle. Service providers are advised to state what they know and do not know, use a single source of truth such as a status page, and focus communications on actionable guidance rather than reputation management. Customers should be told what actions they need to take or clearly informed when no action is required.

The guidance also calls for continuous, time-stamped updates that show the incident timeline, actions taken, and recovery milestones. Organizations should maintain a single status page and align external messaging with legal, contractual and sector-specific reporting obligations.

Agencies ultimately frame effective outage communications around five principles: immediate acknowledgement, technical and actionable information, transparency, accountability, and continuous updates. For service providers, the guidance positions communication as an important part of incident response, alongside technical remediation and recovery.

  • ✇Firewall Daily – The Cyber Express
  • Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns Samiksha Jain
    The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge. According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity
     

Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns

13 de Agosto de 2026, 03:10

sexual exploitation actors

The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.

According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.

The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.

How Sexual Exploitation Actors Access Accounts

The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.

Password and PIN Targeting

In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.

When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.

Social Media Customer Service Impersonation

Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.

The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.

Phishing Emails

The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.

These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.

Stolen Content Can Lead to Further Attacks

Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.

The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.

FBI Shares Steps to Protect Accounts

The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.

It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.

Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.

Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.

People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
  • ✇Firewall Daily – The Cyber Express
  • Gunra Ransomware Builds a New Attack Network Through RaaS Samiksha Jain
    Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant d
     

Gunra Ransomware Builds a New Attack Network Through RaaS

11 de Agosto de 2026, 08:01

Gunra ransomware

Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.

Gunra Ransomware Shifts to Affiliate Model

By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums. The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers. Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting. Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific. Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services. Gunra ransomware

VPN Vulnerabilities Used for Initial Access

According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions. The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access. After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.

Data Theft Precedes Encryption

The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications. In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes. For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.

Agencies Urge Patching and Network Segmentation

The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations. Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems. The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework. The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.
  • ✇Firewall Daily – The Cyber Express
  • FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation Samiksha Jain
    Employment scams are increasingly being used to target job seekers, with the FBI and LinkedIn joining forces to educate applicants about fraudulent job opportunities and the warning signs of potential exploitation. The FBI's Internet Crime Complaint Center received 24,688 reports of employment scam victimization in 2025, with nearly $363 million in reported losses. The FBI defines employment fraud as a scheme designed to deceive someone into believing they have been, or could soon be, hired f
     

FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation

Employment scams

Employment scams are increasingly being used to target job seekers, with the FBI and LinkedIn joining forces to educate applicants about fraudulent job opportunities and the warning signs of potential exploitation. The FBI's Internet Crime Complaint Center received 24,688 reports of employment scam victimization in 2025, with nearly $363 million in reported losses. The FBI defines employment fraud as a scheme designed to deceive someone into believing they have been, or could soon be, hired for a job. However, officials warn that these schemes are not always focused on stealing money from victims. They can also be used to recruit money mules, collect personally identifiable information, or force people into labor.

Employment Scams Exploit Trust in Job Opportunities

LinkedIn, which has more than 1.3 billion members across more than 200 countries and regions, said people submit approximately 10,000 job applications every minute on the platform. The company uses automated systems and human oversight to detect and remove fraudulent activity. According to LinkedIn, automated defenses remove 98.7% of detected spam and scam content before members see it, while 99.5% of detected fake accounts are stopped proactively. LinkedIn also uses verification indicators to show when certain information about people, companies, recruiters, and candidates has been confirmed. Despite these measures, the company said scammers are becoming more sophisticated, with artificial intelligence making it cheaper, faster, and easier to impersonate legitimate individuals. One warning sign highlighted by LinkedIn is when a recruiter or company representative attempts to move a conversation away from LinkedIn's messaging platform. Doing so can allow scammers to bypass the platform's protections and reporting tools.

Money Mule Scams Turn Job Seekers Into Financial Intermediaries

One major form of employment scams involves recruiting victims as money mules. Scammers may advertise legitimate-sounding positions such as cryptocurrency transaction specialist, accounts receivable assistant, remote financial coordinator, or payment processing agent. After being hired, victims may receive money in their personal bank accounts, often through peer-to-peer payment applications. They are then instructed to withdraw the funds, convert them into cash, gift cards, or cryptocurrency, and transfer them elsewhere in exchange for a small commission. The money is generally linked to other scams or compromised accounts. Victims may face legal consequences, account closures, and seized funds despite being deceived into participating.

Stolen PII Employment Scams Target Personal Information

Another type of fraud uses fake employment opportunities to collect stolen PII. Job titles may include onboarding specialist, HR assistant, compliance reviewer, or know your customer and identity verification agent. Victims may be asked to collect identity documents from customers, forward files, verify accounts, handle one-time codes, open accounts, submit applications, or organize data into spreadsheets and shared drives. Instead of directly moving stolen money, victims become part of a process designed to harvest personal information.

Forced Labor Can Begin With a Fake Job Offer

The FBI also warns that some employment scams can become gateways to human trafficking and forced labor. Victims may be offered jobs abroad or remote positions and encouraged to travel internationally, with Southeast Asia identified as a known hotspot. After arriving, victims may have their passports confiscated and be told they must repay travel costs. Some are then forced to work in scam compounds, where they are required to contact targets. Victims may face monitoring, threats, or physical abuse if they fail to meet quotas.

FBI Warns Job Seekers About Employment Scam Red Flags

The FBI and LinkedIn advise applicants to research companies carefully and watch for warning signs. For money mule scams, red flags include requests to use personal bank accounts for business transactions, bypass normal payroll systems, move money quickly, open new accounts, or use cryptocurrency and gift cards. For scams involving stolen PII, applicants should be cautious if they are asked to handle sensitive identity documents without a legitimate compliance structure, receive files through informal channels, or are pressured to bypass normal safeguards. Potential forced labor scams may involve unusually high pay for vague overseas jobs, demands for quick relocation, employer-controlled travel arrangements, vague contracts, early moves to encrypted messaging apps, or instructions to keep the job secret from family. The FBI and LinkedIn said educating job seekers can help disrupt employment fraud before victims become involved. Anyone who believes they have been targeted should contact their financial institution immediately and report the incident to the FBI's Internet Crime Complaint Center with as many details as possible.
  • ✇Firewall Daily – The Cyber Express
  • Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S. Samiksha Jain
    An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group. Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago a
     

Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.

Scattered Spider

An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.

Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.

According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider Linked to More Than 100 Network Intrusions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.

Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.

Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.

Complaint Details Alleged Luxury Retailer Cyberattack

The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.

Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.

Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.

Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.

According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.

Authorities Cite International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.

FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Recent Guidance on Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.

Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).

The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure

Iranian hacker

An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity theft after authorities linked him to a years-long cyber campaign that reportedly caused more than $3.4 billion in damages. 

Iranian Hacker Faces Computer Fraud and Hacking Charges 

The 39-year-old suspect, who holds dual Iranian and Turkish citizenship, was arrested in the Adriatic coastal town of Kotor, Montenegro. According to local police, he is wanted by the Southern District Court of New York on charges of conspiracy to commit computer fraud, hacking, and identity theft.  The case will now be referred to a High Court judge in Montenegro's capital, Podgorica, where extradition proceedings are expected to begin. 

Alleged Cyberattack on USA Universities Caused Billions in Damage 

In an official statement, Montenegro's police directorate alleged that the Iranian hacker had been involved in large-scale hacking operations since 2013.  "From 2013 onward, … he carried out massive hacking attacks … targeting more than 150 universities in the United States, causing damage estimated at over $3.4 billion," the statement said.  Authorities claim the stolen data and access to compromised university accounts were used to benefit Iran's Islamic Revolutionary Guard Corps (IRGC) and other Iranian organizations, including universities. Investigators allege the campaign formed part of a broader cyberattack on USA institutions aimed at acquiring sensitive academic data and digital access. 

Extradition Process Underway 

Following the arrest, Montenegrin authorities confirmed that the suspect remains in custody while legal proceedings continue. If approved, he will be extradited to the United States to face charges tied to computer fraud, identity theft, and extensive hacking operations.  The FBI participated in the investigation that led to the arrest, although the agency was not immediately available for comment after the announcement. 

Iranian Cyber Operations Remain Under Scrutiny 

The latest arrest comes amid continued concerns over Iranian-linked cyber activity. Iran and the IRGC have long been associated with state-sponsored cyber operations targeting U.S. organizations and infrastructure.  In April, U.S. cybersecurity, intelligence, and law enforcement agencies warned that Iranian hacking campaigns targeting equipment across critical U.S. infrastructure had intensified. The warning highlighted an increase in attempted intrusions, reinforcing concerns over future cyberattacks on the USA.  The arrest marks a new development in an international investigation into one of the largest alleged cybercrime cases involving an Iranian hacker, with prosecutors pursuing charges that include conspiracy, computer fraud, hacking, and identity theft linked to billions of dollars in reported losses. 
  • ✇Firewall Daily – The Cyber Express
  • FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware Samiksha Jain
    The FBI Warns of Malicious Traffic Distribution Systems being increasingly used by cybercriminals to redirect internet users to phishing pages, malware downloads, ransomware attacks, and online financial scams. In a newly released Public Service Announcement (PSA), the Federal Bureau of Investigation cautioned that cybercriminals are leveraging Traffic Distribution Systems (TDS) to gain access to victim networks while evading traditional security controls. According to the FBI, TDS technology
     

FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware

FBI Warns of Malicious Traffic

The FBI Warns of Malicious Traffic Distribution Systems being increasingly used by cybercriminals to redirect internet users to phishing pages, malware downloads, ransomware attacks, and online financial scams. In a newly released Public Service Announcement (PSA), the Federal Bureau of Investigation cautioned that cybercriminals are leveraging Traffic Distribution Systems (TDS) to gain access to victim networks while evading traditional security controls. According to the FBI, TDS technology is designed to route internet traffic to different destinations after users visit websites, click advertisements, download applications, or engage with online promotions. While the technology itself has legitimate uses, cybercriminals are exploiting it to selectively redirect users to compromised websites and fraudulent login pages.

FBI Warns of Malicious Traffic Distribution Systems Used in Cyber Attacks

As the FBI Warns of Malicious Traffic Distribution Systems, the agency explained that cybercriminals often drive victims to a malicious TDS through various methods, including Social Engineering, phishing emails, malicious advertisements, and compromised websites. One common technique involves Search Engine Optimization (SEO) Poisoning, where fraudulent advertisements are designed to imitate legitimate websites. Users who click these links may unknowingly enter a redirection chain controlled by threat actors. Cybercriminals also compromise legitimate websites by exploiting weak passwords, outdated plugins, and vulnerable website themes. Once administrative access is obtained, attackers can modify website code to automatically redirect visitors to a malicious TDS infrastructure.

How Traffic Distribution Systems Help Evade Detection

According to the FBI, Traffic Distribution Systems (TDS) can bypass traditional firewall protections that would normally block access to malicious websites. The system uses multiple intermediate nodes before directing users to the final destination, making it more difficult for defenders to identify and block malicious activity. In addition to hiding malicious infrastructure, attackers use TDS platforms to gather information about visitors. Data collected may include:
  • IP address
  • Operating system
  • Geographic location
  • Device information
  • Browser details
The FBI noted that this information allows attackers to determine whether a victim is a suitable target. It also enables cybercriminals to avoid detection by presenting harmless content to users they are not interested in targeting, including security researchers and analysts.

Phishing, Malware, and Ransomware Risks

The FBI warned that users reaching the end of a malicious redirection chain may encounter Phishing Pages, financial fraud schemes, or malware downloads. In some cases, attackers use malware delivered through a TDS to gain access to victim networks. The agency stated that compromised accounts and network access obtained through these methods may later be sold to other criminal groups, including Ransomware operators. The PSA highlights how a single visit to a compromised website or malicious advertisement can ultimately lead to broader cybersecurity incidents.

FBI Shares Protection Measures

To reduce the risk of compromise, the FBI advised individuals to verify website URLs before clicking advertisements or promotional links. The agency also recommended keeping software, website plugins, and themes updated to address known vulnerabilities. Additional recommendations include:
  • Using strong passwords
  • Enabling Two-Factor Authentication (2FA)
  • Installing reputable security plugins and web application firewalls
  • Downloading software only from trusted developers
For businesses, the FBI recommended monitoring endpoints for suspicious activity involving JavaScript, PowerShell, and script execution tools. Organizations are also encouraged to strengthen phishing awareness training, regularly audit website administration accounts, and patch content management systems and third-party components.

FBI Urges Victims to Report Incidents

The FBI encouraged individuals and organizations that believe they have been affected by activity linked to malicious TDS infrastructure to report the incident through the Internet Crime Complaint Center (IC3) and contact their local FBI field office. The agency emphasized that cybercriminals continue to evolve their techniques for delivering malware and conducting online fraud, making vigilance and proactive cybersecurity measures essential for both individuals and businesses.

FIFA World Cup 2026 Scams: Fake Websites, Ticket Fraud, and Job Scams Already Active

FIFA World Cup 2026 scams

The FIFA World Cup 2026 may not kick off until June 11, 2026, but cybercriminals have already begun exploiting anticipation surrounding the tournament. Security researchers and law enforcement agencies are warning that FIFA World Cup 2026 scams are actively targeting fans, job seekers, and businesses through fake websites, phishing campaigns, and fraudulent online services.  The FBI recently issued a Public Service Announcement warning that threat actors are creating fraudulent versions of FIFA-affiliated websites to steal personal information, conduct financial fraud, and sell fake products and services. Researchers at Cyble independently reviewed the FIFA domains identified by the FBI and confirmed that many remained active at the time of analysis.  With 48 teams competing across 16 host cities in the United States, Canada, and Mexico, the tournament is expected to attract billions of viewers worldwide, making it an attractive target for cybercriminal activity. 

Fake FIFA Domains and Typosquatting Attacks 

According to the FBI, attackers are building websites that closely resemble FIFA’s official platform, www.fifa.com. These sites are designed to collect personally identifiable information (PII), including names, addresses, email accounts, banking information, and payment card details.  Many of these operations rely on a typosquatting attack, a technique in which criminals register lookalike FIFA domains featuring slight spelling changes, missing characters, or alternative extensions. Examples identified by the FBI include fifa[.]help, fifa-online[.]com, jobs-fifa[.]com, fifa-ticket[.]live, fifa-hiring[.]com, and ww-fifa[.]com.  Cyble researchers noted that malicious FIFA domains often reappear quickly after takedowns, indicating a continuously evolving fraud infrastructure rather than isolated campaigns. 

Ticket, Hospitality, and Recruitment Fraud 

One of the most convincing examples analyzed by researchers was ww-fifa[.]com, a typosquatting attack that removes a single "w" from the legitimate FIFA address. The site presented itself as an official FIFA World Cup 2026 portal and promoted premium hospitality packages that allegedly included tickets, food, beverages, lounge access, and other services.  Researchers identified several red flags, including broken images, duplicate page titles, suspicious navigation links, and requests for personal and financial information through illegitimate payment forms.  Cyble also uncovered employment-related FIFA World Cup 2026 scams. The domain fifaworldcup-careers[.]com impersonated a FIFA recruitment portal offering World Cup-related positions. VirusTotal data showed that the website was flagged by 8 of 91 security vendors, while the root domain was flagged by 14 of 91 vendors. [caption id="" align="aligncenter" width="936"]Fake FIFA 2026 domain scoring Fake FIFA 2026 domain scoring (Source: Cyble)[/caption] WHOIS records revealed that the domain was registered and updated in April 2026, with the registrant's identity hidden behind privacy protection services. Researchers also found two SSL certificates issued on April 15 and April 16, including a wildcard certificate covering subdomains.

How Fans Can Stay Safe 

The FBI advises users to type www.fifa.com directly into their browser rather than relying on search engine results, sponsored advertisements, or links received through messages. Users should verify URLs carefully, save official pages as bookmarks, and avoid sharing sensitive information unless a site's legitimacy has been independently confirmed.  The agency also warns that fraudulent streaming platforms are likely to increase as the tournament approaches. Fans should rely only on official FIFA channels and licensed broadcasters when searching for FIFA World Cup 2026 content.  Anyone who encounters a suspected scam should preserve screenshots, domain information, communication records, and payment details before reporting the incident to the Internet Crime Complaint Center (IC3). With FIFA World Cup 2026 scams already active and new FIFA domains appearing regularly, experts warn that vigilance will be critical throughout the tournament period. 
  • ✇Firewall Daily – The Cyber Express
  • FBI Flags Kali365 as New Phishing Threat Targeting Microsoft 365 Users Samiksha Jain
    The FBI has issued a fresh warning about a growing cybercrime service known as Kali365, a new Phishing-as-a-Service (PhaaS) platform that enables attackers to hijack Microsoft 365 accounts without stealing passwords directly. According to the FBI, the Kali365 phishing kit allows even low-skilled cybercriminals to bypass multi-factor authentication (MFA) protections by abusing Microsoft’s legitimate device authentication workflow. The platform, which surfaced in April 2026, is being distribute
     

FBI Flags Kali365 as New Phishing Threat Targeting Microsoft 365 Users

Kali365 Phishing Kit

The FBI has issued a fresh warning about a growing cybercrime service known as Kali365, a new Phishing-as-a-Service (PhaaS) platform that enables attackers to hijack Microsoft 365 accounts without stealing passwords directly. According to the FBI, the Kali365 phishing kit allows even low-skilled cybercriminals to bypass multi-factor authentication (MFA) protections by abusing Microsoft’s legitimate device authentication workflow. The platform, which surfaced in April 2026, is being distributed primarily through Telegram channels and is already being linked to hundreds of phishing campaigns targeting organizations and individuals worldwide. Instead of collecting usernames and passwords, attackers steal OAuth access tokens that provide long-term access to Microsoft 365 environments, including Outlook, Teams, and OneDrive.

How the Kali365 Phishing Kit Works

The FBI explained that the platform relies on a deceptive but technically simple attack chain designed to exploit user trust. The process typically begins with a phishing email impersonating trusted productivity or document-sharing services. The email contains a device authentication code and instructions asking the victim to visit a legitimate Microsoft verification page. Because the webpage itself is genuine, many users assume the request is safe. Once the targeted user enters the provided code, they unknowingly authorize the attacker’s device to access their Microsoft 365 account. The attacker then captures OAuth access and refresh tokens, enabling persistent access without requiring the victim’s password or additional MFA verification. This technique is particularly dangerous because it does not rely on traditional credential theft. Instead, it abuses Microsoft’s authentication framework to gain legitimate session access. The FBI noted that after successful token capture, attackers can continue accessing services such as Outlook email accounts, Teams communications, and OneDrive files without triggering additional login prompts.

Why OAuth Token Theft Is Becoming a Growing Threat

Security researchers say OAuth token theft is becoming increasingly popular among cybercriminals because it allows attackers to bypass many traditional security controls. Unlike passwords, OAuth tokens are designed to maintain authenticated sessions across services. If stolen, they can provide attackers with ongoing access until revoked or expired. The FBI warned that Kali365 significantly lowers the barrier to entry for cybercrime operations by offering built-in phishing templates, AI-generated phishing lures, automated campaign tools, and real-time dashboards that track victims and stolen tokens. This means attackers no longer need advanced technical expertise to launch phishing campaigns against businesses using Microsoft 365 environments. The platform’s availability on Telegram also makes it easier for threat actors to distribute and monetize phishing infrastructure at scale.

FBI Shares Protection Measures Against Kali365 Attacks

To reduce exposure to these attacks, the FBI advised organizations to restrict or block device code authentication flows wherever possible. One of the key recommendations includes implementing conditional access policies that block device code flow for most users while allowing limited exceptions for essential business operations. Organizations are also encouraged to audit existing device authentication workflows to identify legitimate dependencies before enforcing restrictions. The FBI further recommended blocking authentication transfer policies that allow authentication to move between computers and mobile devices, as these workflows can potentially be abused during phishing attacks. For organizations unable to fully disable device code flow, the agency suggested excluding emergency access accounts from restrictions to avoid accidental lockouts during critical situations.

FBI Urges Victims to Report Incidents

The FBI is urging anyone impacted by the Kali365 phishing campaign to report incidents through the Internet Crime Complaint Center (IC3). Victims are encouraged to preserve and submit phishing emails, suspicious login activity, unauthorized devices, IP addresses, and active session information that could assist investigators. The agency also pointed users toward phishing mitigation guidance published by the Cybersecurity and Infrastructure Security Agency, which outlines defensive measures organizations can take to reduce phishing risks. The rise of Kali365 Phishing-as-a-Service highlights how cybercriminals are increasingly shifting toward token-based attacks that exploit trusted authentication systems instead of relying solely on password theft. As phishing platforms continue evolving, security experts warn that organizations using cloud productivity platforms like Microsoft 365 will need stronger identity protection measures and closer monitoring of authentication activity to reduce the risk of account compromise.
  • ✇Firewall Daily – The Cyber Express
  • FBI Warns of Surge in Cyber-Enabled Cargo Theft Targeting Logistics Firms Samiksha Jain
    The Federal Bureau of Investigation (FBI) has issued a public warning over a sharp rise in cyber-enabled cargo theft, as threat actors increasingly use digital tactics to impersonate legitimate businesses, hijack freight, and steal high-value shipments. According to the FBI, cybercriminals are targeting transportation and logistics companies involved in shipping, receiving, and insuring cargo. The agency said these attacks have been ongoing since at least 2024 and are now becoming more sophis
     

FBI Warns of Surge in Cyber-Enabled Cargo Theft Targeting Logistics Firms

cyber-enabled cargo theft

The Federal Bureau of Investigation (FBI) has issued a public warning over a sharp rise in cyber-enabled cargo theft, as threat actors increasingly use digital tactics to impersonate legitimate businesses, hijack freight, and steal high-value shipments. According to the FBI, cybercriminals are targeting transportation and logistics companies involved in shipping, receiving, and insuring cargo. The agency said these attacks have been ongoing since at least 2024 and are now becoming more sophisticated and widespread. Losses linked to cyber-enabled cargo theft have surged significantly. In 2025, estimated cargo theft losses in the United States and Canada reached nearly $725 million, marking a 60 percent increase from the previous year. Confirmed incidents rose by 18 percent, while the average value per theft increased by 36 percent to $273,990, reflecting a shift toward more targeted, high-value shipments.

How Cyber-Enabled Cargo Theft Works

The FBI outlined a structured, multi-step process used in cyber-enabled cargo theft schemes. Attackers begin by compromising accounts of brokers and carriers through phishing techniques such as spoofed emails, fake websites, and malicious links. Victims are often sent emails posing as legitimate business communications, such as carrier agreements or service complaints. These emails include links that lead to phishing websites designed to mimic trusted platforms. Once accessed, these sites deploy malware or remote monitoring tools, allowing attackers to gain full control over systems without detection. After gaining access, cybercriminals exploit online freight marketplaces known as load boards. They impersonate legitimate brokers or carriers and post fake shipment listings, sometimes in large volumes. Unsuspecting carriers bid on these listings and are further compromised through fraudulent agreements or malicious downloads. In the next stage, attackers use the compromised accounts to accept real shipment contracts. They then engage in illegal double-brokering, rerouting freight to unintended locations. Shipment documents are manipulated, including bills of lading, and delivery destinations are altered without the knowledge of the original parties. The final stage of cyber-enabled cargo theft involves physically diverting the cargo. Goods are transferred through cross-docking or transloading to other drivers, often complicit, and then stolen for resale. In some cases, attackers demand ransom payments in exchange for information about the shipment’s location. [caption id="attachment_111803" align="aligncenter" width="972"]cyber-enabled cargo theft Image Source: https://www.ic3.gov/[/caption]

Indicators of Cyber-Enabled Cargo Theft

The FBI has identified several warning signs that may indicate a cyber-enabled cargo theft attempt. These include unexpected communications regarding shipments made in a company’s name, spoofed email domains, and requests to download documents from suspicious links. Other indicators include emails referencing negative service reviews with embedded links, unauthorized changes to email account settings, and slight variations in domain names designed to mimic legitimate organisations. Attackers may also use temporary or internet-based phone numbers to communicate with victims. These tactics are designed to create a sense of urgency or legitimacy, increasing the likelihood that employees will engage with malicious content.

Steps to Prevent Theft

To reduce the risk of cyber-enabled cargo theft, the FBI is urging organisations to adopt stronger verification and security practices. Companies are advised to independently confirm shipment requests using multiple communication channels before releasing goods. The agency recommends implementing multi-layer verification processes and not relying solely on familiar names or email addresses. Businesses should also maintain detailed records of all transactions, including driver identification, vehicle details, and communication logs, to support investigations if needed. Recognising phishing attempts and avoiding interaction with suspicious links remain critical preventive measures.

Reporting Theft Incidents

The FBI has encouraged victims of cyber-enabled cargo theft to report incidents promptly. In addition to contacting local law enforcement, affected organisations should file complaints with the Internet Crime Complaint Center (IC3) or reach out to their nearest FBI field office. The agency said timely reporting can help identify patterns, disrupt criminal networks, and prevent further losses across the logistics sector.

Dubai Police Smash International Scam Empire in Massive FBI and China-Led Operation

Operation Tri-Force Sentinel

In a major international enforcement action, Operation Tri-Force Sentinel, led by Dubai Police, in coordination with the FBI and Chinese Police, has dismantled a large transnational fraud network involved in global financial scams. The Operation Tri-Force Sentinel crackdown resulted in the arrest of 276 individuals linked to organised cyber-enabled fraud activities spanning multiple countries, primarily involving suspects from Southeast Asia. The Operation Tri-Force Sentinel was carried out under the UAE Ministry of Interior and focused on disrupting criminal syndicates running high-yield investment scams, commonly known as HYIS, “pig butchering” schemes, and virtual currency fraud. Authorities confirmed that nine major fraud centres were dismantled during the coordinated action.

276 Arrests and Nine Fraud Centres Dismantled in Operation Tri-Force Sentinel

As part of the operation, law enforcement agencies executed synchronized raids that dismantled three major criminal syndicates operating fraud centres. These centres were responsible for large-scale financial deception campaigns targeting victims across several regions. The operation led to the arrest of 276 suspects, with authorities confirming that the network used advanced social engineering techniques. Victims were reportedly engaged through digital platforms, where trust was gradually built before financial exploitation took place. Dubai Police also confirmed the arrest of a key leader of one of the syndicates in Thailand, carried out in coordination with the Royal Thai Police. The enforcement action marked one of the most significant coordinated strikes against cyber-financial crime groups in recent times under Operation Tri-Force Sentinel. [caption id="attachment_111753" align="aligncenter" width="553"]Operation Tri-Force Sentinel Image Source: Dubai Police[/caption]

Dubai Police, FBI, and Chinese Police Coordination 

Dubai Police played a central role in directing and executing Operation Tri-Force Sentinel, enabling real-time intelligence sharing between international partners. The collaboration with the FBI and Chinese Police was described as critical to the success of the operation. Dubai Police stated that the operation reflects a proactive strategy to combat evolving transnational financial crime threats. The agency emphasized that coordinated international efforts were essential to dismantling complex criminal networks operating across borders. The FBI highlighted the significance of joint enforcement efforts, stating that the operation demonstrates the effectiveness of coordinated global action in disrupting large-scale fraud schemes. It further noted that the partnership with the UAE authorities, particularly the Dubai Police, played a key role in achieving operational success. Chinese Police also reaffirmed their commitment to combating telecom and financial fraud crimes. They emphasized continued cooperation with global law enforcement agencies to address emerging cross-border criminal activities targeted in Operation Tri-Force Sentinel.

Transnational Fraud Networks and Financial Crime Disruption

The dismantled network operated multiple fraud centres using structured and organised digital fraud models. These included investment scams and cryptocurrency-related fraud schemes that have increasingly affected victims across several countries. Authorities noted that the criminal groups involved in Operation relied heavily on psychological manipulation and digital engagement strategies to execute financial scams at scale. The coordinated enforcement action disrupted key operational infrastructure of these networks in a single phase.

International Cooperation Strengthened 

This operation highlights the growing importance of international cooperation in tackling financial crime networks that operate beyond national borders. The joint action between Dubai Police, the FBI, and the Chinese Police demonstrates strengthened coordination in intelligence sharing and enforcement execution. Officials involved in the operation emphasized that continued collaboration is essential to countering sophisticated fraud networks. The success of Operation reflects the ability of global law enforcement agencies to respond jointly to complex cyber-enabled financial threats. The operation marks a significant step in global efforts to combat organised fraud networks and reinforces the role of coordinated international enforcement in addressing cross-border financial crime.
  • ✇Firewall Daily – The Cyber Express
  • FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks Ashish Khaitan
    The Russian-linked threat group APT28 has continued to leverage vulnerable network devices to carry out large-scale DNS hijacking campaigns, enabling adversary-in-the-middle attacks. Recent developments show that these operations have drawn direct intervention from U.S. authorities.  The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a network of compromised routers controlled by Russia’s military intelligence unit, widely known as APT28. According to
     

FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks

APT28

The Russian-linked threat group APT28 has continued to leverage vulnerable network devices to carry out large-scale DNS hijacking campaigns, enabling adversary-in-the-middle attacks. Recent developments show that these operations have drawn direct intervention from U.S. authorities.  The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a network of compromised routers controlled by Russia’s military intelligence unit, widely known as APT28. According to findings aligned with prior reporting from the NCSC, the group has been exploiting routers to intercept communications, harvest credentials, and target individuals and organizations of intelligence interest. 

DNS Hijacking and Adversary-in-the-Middle Tactics 

APT28’s operations include DNS hijacking, a technique that manipulates how domain names are resolved into IP addresses. By altering DNS settings, often at the router level, attackers redirect legitimate traffic through malicious infrastructure. This enables adversary-in-the-middle (AitM) attacks, where victims unknowingly connect to spoofed services. These malicious endpoints are designed to imitate legitimate platforms, allowing attackers to intercept login sessions and extract sensitive data, including passwords, OAuth tokens, and emails. Both the FBI and the NCSC have noted that these attacks can impact browser sessions and desktop applications alike, increasing the scale and effectiveness of credential harvesting.

U.S. Operation Targets APT28 Infrastructure 

The disruption effort, publicly disclosed by the Department of Justice, targeted a network of small office/home office (SOHO) routers compromised by APT28, also known as Fancy Bear, Sofacy, Sednit, STRONTIUM, Forest Blizzard, and Pawn Storm. The group is widely attributed to Russia’s GRU Unit 26165.  Since at least 2024, APT28 actors have exploited known vulnerabilities to gain access to thousands of TP-Link routers globally. After stealing credentials, they modified router configurations to redirect DNS traffic to malicious servers under their control. These operations were initially indiscriminate. However, the attackers implemented automated filtering mechanisms to identify DNS queries of intelligence value. For selected targets, the malicious DNS resolvers returned fraudulent records for domains, particularly those mimicking Microsoft Outlook services, to facilitate adversary-in-the-middle attacks against encrypted traffic.  Through this approach, APT28 was able to harvest unencrypted passwords, authentication tokens, emails, and other sensitive data from devices connected to compromised routers.

Official Statements on the Threat 

U.S. officials described the campaign as both persistent and dangerous. Assistant Attorney General John A. Eisenberg stated, “The GRU’s predatory use of networks in American homes and businesses for its malicious cyber operations remains a serious and persistent threat.”  U.S. Attorney David Metcalf added, “Russian military intelligence once again hijacked Americans’ hardware to commandeer critical data,” emphasizing that the government would continue to respond aggressively to nation-state cyber threats.  FBI officials also stressed the scale of the campaign. Assistant Director Brett Leatherman noted that compromised routers were used globally for espionage, while Special Agent Ted E. Docks highlighted that devices across more than 23 U.S. states had been weaponized. 

How the FBI Disrupted the DNS Hijacking Network 

As part of the court-authorized operation, referred to as Operation Masquerade, the FBI deployed technical measures to neutralize the U.S. portion of APT28’s infrastructure.  According to court documents: 
  • The FBI sent commands to compromised routers to collect evidence of APT28 activity. 
  • Reset DNS settings, removing malicious resolvers and restoring legitimate ISP configurations.
  • Blocked the actors’ ability to regain unauthorized access. 
The operation was carefully tested on affected TP-Link devices to ensure that it did not disrupt normal functionality or collect user content. Importantly, the remediation steps can be reversed by users through factory resets or manual configuration changes. 

Continued Router Exploitation and Infrastructure Tactics 

These developments align closely with earlier findings from the NCSC, which documented how APT28 used Virtual Private Servers (VPSs) as malicious DNS infrastructure. Two main clusters were identified: 
  • Cluster One: Focused on modifying DHCP DNS settings in SOHO routers, enabling selective DNS hijacking and adversary-in-the-middle attacks.  
  • Cluster Two: Involved forwarding DNS traffic through a layered infrastructure, with some operations targeting high-value devices, including those in Ukraine.  
APT28’s activity has also included exploitation of vulnerabilities such as CVE-2023-50224 in TP-Link routers, allowing attackers to extract credentials and reconfigure DNS settings via crafted HTTP requests.

Targeted Services and Indicators 

APT28’s DNS hijacking campaigns have frequently targeted Microsoft Outlook-related domains, including: 
  • autodiscover-s.outlook[.]com  
  • imap-mail.outlook[.]com  
  • outlook.live[.]com  
  • outlook.office[.]com  
  • outlook.office365[.]com  
These targets reflect a clear focus on email-based intelligence gathering. Supporting infrastructure includes numerous malicious IP ranges and identifiable server configurations, such as unusual SSH ports and “dnsmasq-2.85” DNS services. 

Mitigation and Security Recommendations 

Both the FBI and the NCSC recommend immediate steps to mitigate risks associated with DNS hijacking and adversary-in-the-middle attacks: 
  • Replace end-of-life or unsupported routers  
  • Update firmware to the latest available versions  
  • Verify DNS settings to ensure they point to legitimate resolvers  
  • Disable or secure remote management interfaces  
  • Implement firewall rules to limit exposure  
  • Enable multi-factor authentication (MFA) to reduce credential abuse  
  • Users are also encouraged to monitor their networks and report suspected compromises to appropriate authorities. 
  • ✇Firewall Daily – The Cyber Express
  • Iran-Linked Hackers Breach U.S. Industrial Systems, Trigger Disruptions Samiksha Jain
    A new U.S. government advisory has raised fresh concerns over Iranian-affiliated APT targeting PLCs, warning that cyberattacks are now moving beyond data theft into direct disruption of industrial systems. Issued on April 7, 2026, the joint alert from the FBI, CISA, NSA and other agencies confirms that Iran-linked threat actors are actively exploiting internet-facing programmable logic controllers (PLCs), with incidents already impacting multiple critical infrastructure sectors. This is no
     

Iran-Linked Hackers Breach U.S. Industrial Systems, Trigger Disruptions

Iranian-affiliated APT targeting PLCs

A new U.S. government advisory has raised fresh concerns over Iranian-affiliated APT targeting PLCs, warning that cyberattacks are now moving beyond data theft into direct disruption of industrial systems. Issued on April 7, 2026, the joint alert from the FBI, CISA, NSA and other agencies confirms that Iran-linked threat actors are actively exploiting internet-facing programmable logic controllers (PLCs), with incidents already impacting multiple critical infrastructure sectors. This is not a theoretical threat. According to the advisory, several organizations have experienced operational disruptions and even financial losses after attackers interfered with industrial processes.

From Network Access to Operational Disruption

What makes this campaign stand out is its intent. The Iranian-affiliated APT targeting PLCs activity is not focused on espionage, it is designed to disrupt. Attackers have been manipulating PLC project files and altering data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) systems. In practice, this means operators could be relying on inaccurate data while underlying processes are being changed in real time. The affected sectors include government services, water and wastewater systems, and energy, areas where even minor disruptions can have significant downstream impact. [caption id="attachment_111119" align="aligncenter" width="600"]Iranian-affiliated APT targeting PLCs Image Source: FBI[/caption]

How the Attacks Are Carried Out

The entry point is often simple: internet exposure. The advisory notes that attackers are scanning for publicly accessible PLCs, particularly models such as CompactLogix and Micro850—and connecting to them using legitimate engineering tools like Studio 5000 Logix Designer. Once inside, the activity becomes more deliberate. Threat actors extract configuration files, modify logic, and establish persistence. In some cases, they deploy tools like Dropbear SSH to maintain remote access through port 22. The attacks rely on commonly used industrial communication ports, including 44818, 2222, 102, 22, and 502, allowing malicious traffic to blend in with normal OT operations. Investigators also observed the use of overseas IP addresses and leased third-party infrastructure, suggesting a coordinated and sustained effort rather than opportunistic scanning.

A Campaign That Has Been Building Over Time

The current activity is not happening in isolation. U.S. agencies link it to earlier Iran-aligned operations, including campaigns attributed to the CyberAv3ngers group that targeted PLCs in 2023. What has changed is the persistence. The latest advisory tracks activity spanning from at least January 2025 through March 2026, with ongoing incidents reported as recently as March. Officials suggest the escalation may be tied to broader geopolitical tensions, but the technical pattern is clear: industrial control systems are becoming a repeated target.

Exposure and Weak OT Security

The Iranian-affiliated APT targeting PLCs campaign exposes a long-standing weakness in critical infrastructure, too many industrial devices remain directly accessible from the internet. In many cases, attackers did not need sophisticated exploits. They gained access because systems lacked basic protections like network segmentation, strong authentication, or restricted remote access. The result is a dangerous scenario where adversaries can move from initial access to operational control with relatively little resistance.

What Organizations Are Being Urged to Do

The advisory calls for immediate action, starting with visibility. Organizations are urged to review logs for suspicious traffic, especially connections originating from overseas infrastructure, and check for unusual activity on key OT ports. More broadly, the guidance reinforces a set of practical steps: removing PLCs from direct internet exposure, routing access through secure gateways, enabling stronger authentication controls, and maintaining offline backups of PLC logic and configurations. In some cases, even operational settings matter, such as ensuring controllers remain in “run” mode to prevent unauthorized remote changes.

A Shift in Cyber Threat Priorities

The bigger takeaway is the shift in attacker focus. By targeting PLCs, threat actors are going straight to the systems that control physical processes. This marks a move from cyber intrusion to potential real-world disruption. The advisory also highlight the role of manufacturers, urging a stronger push toward “secure-by-design” systems that are not exposed by default. For now, the warning is clear: as long as industrial systems remain exposed, campaigns like Iranian-affiliated APT targeting PLCs are likely to continue, and could become more disruptive over time.
❌
❌