Connect with us

CyberSecurity

Why Iran’s Hackers Are No Longer Just Targeting Power Grids and Pipelines

Published

on

Iran cyber threats

The Old Playbook Is Outdated

For years, the conventional wisdom held that Iran’s state-sponsored hackers mainly went after big, obvious targets: power plants, water utilities, oil refineries. The logic was simple. Disrupt a nation’s critical infrastructure and you create real-world chaos without firing a shot. But that focus is shifting — and the shift matters for every company with a server connected to the public internet.

Iranian cyber groups are broadening their scope. They’re no longer laser-focused on critical infrastructure alone. The new reality: if your organization has any internet-facing vulnerability, you’re a potential target. Obscurity is not a defense. A small logistics firm, a regional hospital, a mid-sized manufacturer — all are now in the crosshairs.

Why the Expansion?

Several factors drive this evolution. First, Iran’s cyber apparatus has matured. Groups like APT33, APT34 (OilRig), and affiliated hacktivist personas have built sophisticated toolkits and operational experience. They can pivot faster than ever.

Second, the geopolitical calculus has changed. With sanctions tightening and regional tensions simmering, Tehran sees cyber operations as a low-cost, high-impact lever. Hitting a power grid makes headlines. But quietly compromising dozens of smaller targets — stealing data, deploying ransomware, establishing persistent access — can yield intelligence, leverage, and revenue without triggering a massive response.

Third, the attack surface has exploded. Remote work, cloud migration, and IoT proliferation mean more exposed systems than ever. Many of these belong to organizations that never considered themselves likely targets. They do not have the cybersecurity budgets of a national grid operator.

From Espionage to Extortion

The tactics are evolving too. Traditional Iranian operations focused on espionage and sabotage. Today, you see a wider mix. Ransomware deployments by groups with Iranian fingerprints are on the rise. Data theft for extortion is common. Hacktivist fronts launch DDoS attacks and defacements against perceived enemies of the regime.

Take the recent campaigns targeting Albanian government infrastructure, or the ongoing intrusions into Israeli water and energy sectors. These are not isolated incidents. They signal a willingness to hit any connected target that serves a strategic or tactical purpose.

What This Means for Your Organization

If you run an IT security team, the message is blunt: stop assuming you are too small or too boring to attract attention. Iranian threat actors are scanning the internet constantly. They look for unpatched vulnerabilities, exposed RDP ports, weak credentials, misconfigured cloud storage. When they find one, they probe. If the door opens, they walk in.

The initial access might not be used immediately. Often, attackers establish a foothold and wait — mapping the network, stealing credentials, identifying valuable data. The attack may unfold weeks or months later.

Practical Steps to Reduce Risk

Defending against this expanded threat landscape does not require a spy agency budget. It does require discipline and prioritization. Here are concrete measures every organization should take:

  • Patch aggressively. Prioritize internet-facing systems. Known vulnerabilities are the #1 entry vector for Iranian groups. Automate patching where possible.
  • Reduce the attack surface. Audit every public-facing service. If it does not need to be on the internet, take it offline. Use VPNs and zero-trust architectures.
  • Harden authentication. Enforce multi-factor authentication everywhere, especially on remote access and administrative accounts. Iranian actors are skilled at credential theft.
  • Monitor for unusual activity. Look for lateral movement, unusual outbound connections, and unexpected data transfers. Basic network monitoring catches many intrusions early.
  • Have an incident response plan. Test it. Know who to call if you find a compromise. Speed matters.

The Bigger Picture

Iran’s cyber expansion is part of a global trend. State-sponsored groups everywhere are moving beyond traditional targets. The lines between espionage, crime, and sabotage are blurring. For defenders, the key takeaway is simple: you cannot rely on being overlooked. The internet is a flat battlefield. Vulnerabilities are opportunities — and adversaries are scanning for them 24/7.

Understanding Iranian cyber threat evolution is no longer niche knowledge for national security experts. It is basic risk management for any connected business. The question is not whether you will be scanned. It is whether you will be ready when the scan finds something.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

New HollowGraph Malware Turns Microsoft 365 Calendars Into a Covert Command Channel

Published

on

HollowGraph malware

Malware Finds a New Hideout: Your Work Calendar

A newly discovered strain of malware is doing something that sounds almost too clever to be real: it uses a compromised Microsoft 365 calendar as its command-and-control (C&C) channel. Researchers at Group-IB have named it HollowGraph, and its trick is both elegant and deeply unsettling for any organization that lives inside the Microsoft ecosystem.

The malware doesn’t phone home to some shady server in a far-off data center. Instead, it talks to its operators by reading and writing calendar events on a legitimate business account. The whole thing runs through the Microsoft Graph API, making the malicious traffic look like ordinary Office 365 sync activity.

How HollowGraph Turns a Calendar Into a Dead-Drop

The technique is straightforward in concept but vicious in execution. HollowGraph takes over a victim’s mailbox — in this case, one belonging to an Israeli organization — and uses its calendar as a two-way drop box. Attackers plant new instructions by creating calendar events. The malware, in turn, exfiltrates stolen files by creating its own events with encrypted payloads attached.

These events are dated far in the future — specifically, May 13, 2050. The logic is simple: a calendar event three decades away won’t show up on anyone’s daily agenda. It sits quietly in the background, invisible to the legitimate user, while the malware reads and writes data at will. Payloads are encrypted using a hybrid RSA + AES scheme, so even if someone stumbles onto the event, they can’t read its contents.

HollowGraph supports just two commands: ‘send’ and ‘get’. The ‘send’ command creates a new appointment with an attached file for exfiltration. The ‘get’ command searches for appointments planted by the operator and downloads new instructions. It’s a minimal, purpose-built system — and that’s exactly what makes it hard to spot.

Secondary Channel and Configuration Details

Group-IB found that HollowGraph doesn’t rely solely on the calendar trick. It maintains a secondary communication channel using DNS tunneling to refresh its configuration and update the Microsoft Entra ID (formerly Azure AD) credentials used for authentication. This fallback ensures the malware can still operate even if the primary calendar channel is disrupted.

Upon execution, HollowGraph writes its hardcoded configuration to disk as a file named logAzure.txt. That configuration includes the Entra ID tenant ID, a client ID and secret, the target mailbox address, the C&C domain, and two RSA keys. It’s a complete operational package — the malware never needs to reach out to an attacker-controlled server for initial payload delivery.

Victim Profile: A Focused Campaign, Not a Spray-and-Pray

The evidence points to a narrow, deliberate targeting. Group-IB identified 12 victims, three of which were actively communicating with attacker infrastructure at the time of discovery. The earliest observed communication dates to June 3, suggesting the malware has been operational for roughly six weeks.

Key indicators — including the compromised Israeli mailbox used for exfiltration and malware samples uploaded from Israel — suggest the attackers are laser-focused on Israeli entities. This isn’t a broad, opportunistic campaign. It’s a surgical operation aimed at specific targets.

Attribution: Likely Iran-Nexus, But With Low Confidence

Attribution is always a messy business, and HollowGraph is no exception. Group-IB believes the malware is part of a variant of the Cavern framework, which Check Point detailed earlier this month under the name Cavern Manticore. That framework is linked to an Iran-nexus threat actor.

However, Group-IB is careful to note that it attributes HollowGraph to the Lyceum subgroup (also known as Hexane and SiameseKitten) with low confidence. Lyceum is itself a subgroup of the broader OilRig cluster, which is tied to Iran’s Ministry of Intelligence and Security (MOIS). The researchers found technical similarities — command format, structural patterns — but nothing unique enough for a high-confidence link.

“Based on the evidence currently available, we cannot confidently attribute this activity to any previously identified threat actor,” Group-IB notes in its report. “While these overlaps are noteworthy, they are not sufficiently unique to support a high-confidence attribution.”

What This Means for Defenders

The HollowGraph technique is a reminder that attackers are constantly looking for legitimate services to hide in. Microsoft 365 is so deeply embedded in enterprise workflows that security teams rarely scrutinize calendar API traffic. That’s exactly the blind spot HollowGraph exploits.

For defenders, the key takeaway is to monitor API activity — not just email and file transfers. Anomalous calendar event creation, especially events dated far in the future with unexpected file attachments, should raise red flags. Organizations using Microsoft 365 should also review which applications and service principals have Graph API permissions and audit for any that don’t match known, approved tools.

The days of looking only at network traffic for C&C are long gone. When malware can hide inside your own calendar, the perimeter has moved — and it’s sitting right there in your Outlook folder.

Continue Reading

CyberSecurity

Meta’s new AI tool lets anyone pull your public Instagram photos into generated images — and it’s on by default

Published

on

Meta AI image generation

Your public Instagram photos just became AI training material — whether you opted in or not

Meta has quietly rolled out a new artificial intelligence tool called Muse Image that can pull from public Instagram posts and Reels to generate AI content. The catch? It’s enabled by default for every user. That means your public vacation shots, food pics, and even selfies could be remixed into AI-generated images without you lifting a finger — or giving explicit permission.

The company confirmed the feature in a blog post, framing it as a creative tool. “You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images,” Meta wrote. The idea is to let people design personalized content — think custom event invitations, birthday cards, or stylized mashups of friends’ faces. But the privacy implications are raising eyebrows.

How Muse Image works — and what Meta’s not telling you

Muse Image is an AI model trained on publicly available Instagram data. When you tag a friend’s Instagram handle in a prompt, the system scans that person’s public posts and Reels to generate a new image that incorporates visual elements from their profile. Meta describes this as a way to “bring specific Instagram profiles right into your images,” but the underlying mechanics are more invasive than the marketing suggests.

Here’s what happens in practice:

  • Your public Instagram photos become part of a dataset Muse Image can reference.
  • Anyone can @-mention your handle in a Meta AI prompt to pull your visual style or even specific elements from your posts.
  • The feature is enabled by default — you must manually disable it in settings if you don’t want your content used.

Meta has not published a full list of data types Muse Image accesses, nor has it clarified whether the model retains individual images or simply learns patterns from them. The company says it uses “publicly available” content, but that’s a broad bucket that includes everything from your tagged location to the filters you apply.

Privacy concerns: what happens when your face becomes a prompt

The biggest worry is consent. Meta’s default-on approach means millions of Instagram users are now part of an AI training system they never agreed to. Even if you’ve never touched an AI tool, your public photos can be used to generate new images that you have no control over. And because the feature relies on @-mentions, anyone with your handle can trigger the process.

Privacy advocates have long criticized Meta for vague data-use policies. This move amplifies those concerns. “It’s one thing to train an AI on public images,” says digital rights researcher Elena Torres, “but it’s another to let users actively generate new content using someone else’s likeness without their explicit opt-in.” Meta counters that the feature only accesses public posts — if your account is private, you’re not affected. But for the billions of public Instagram profiles, the default is participation.

There’s also the question of misuse. Could someone use Muse Image to create embarrassing or harmful images of a public figure? Meta says it has safety filters, but the company’s track record with content moderation suggests those guardrails may be porous.

How to opt out of Meta’s AI image generation — before it’s too late

If you don’t want your public Instagram content feeding Muse Image, you can disable the feature. Here’s how:

  1. Open the Instagram app and go to your profile.
  2. Tap the three-line menu (hamburger icon) in the top right corner.
  3. Select Settings and privacy.
  4. Scroll to Account and tap Data usage.
  5. Look for the option labeled Allow your public content to be used in AI generation (or similar wording — Meta may update the label).
  6. Toggle it off.

Note that this only applies to future content. Meta has not clarified whether images already processed by Muse Image will be retroactively removed from the model. The company also hasn’t provided a way to request deletion of specific generated outputs that include your likeness.

For comparison, WhatsApp HD photo sending and other Meta features have faced similar criticism for default-on settings that users only discover later. The pattern is consistent: Meta launches a new capability, makes it active by default, and waits for users to find the off switch.

What this means for the future of AI and social media

Muse Image is part of a broader push by Meta to embed generative AI into its platforms. The company has already integrated AI chatbots, image editing tools, and personalized stickers into Instagram and Facebook. Muse Image takes that one step further by treating user profiles as raw material for AI creation.

The move raises fundamental questions about ownership. Who owns an AI-generated image that uses elements from your public Instagram photos? Meta’s terms of service grant the company a broad license to use your content, but the legal boundaries around AI-generated derivatives are still murky. Courts are only beginning to grapple with cases about AI training data and copyright.

For now, the practical advice is simple: if you value your visual privacy on Instagram, check your settings today. And think twice before posting anything publicly that you wouldn’t want remixed by an AI — because Meta’s new tool makes that remix just a @-mention away.

Continue Reading

CyberSecurity

Microsoft Clamps Down on ‘RoguePlanet’ Zero-Day After Researcher Publishes Exploit Code

Published

on

RoguePlanet zero-day

The Researcher Who Dropped the Bomb

In early June, a security researcher going by the handle Nightmare-Eclipse published a proof-of-concept (PoC) exploit for a critical vulnerability in Microsoft‘s built-in antivirus, Windows Defender. The exploit, which the researcher dubbed RoguePlanet, was the latest in a string of zero-day disclosures from the same individual. Microsoft has now released a patch to neutralize the threat.

The timing wasn’t accidental. Nightmare-Eclipse dropped the PoC code shortly after revealing several other Microsoft zero-days, putting the company on notice. The move forced Microsoft’s hand, accelerating a fix that might otherwise have taken weeks.

What Is the RoguePlanet Vulnerability?

The flaw sits deep inside Windows Defender’s scanning engine. In technical terms, it’s a memory corruption issue that can be triggered when the antivirus processes a specially crafted file. An attacker who successfully exploits it could crash the Defender service — or potentially execute arbitrary code with system-level privileges.

That’s the nightmare scenario: a machine running fully updated Windows, with Defender active, could still be compromised. The researcher’s PoC demonstrated exactly how to trigger the crash, proving the vulnerability was real and exploitable.

How Windows Defender Users Are Affected

Anyone running a recent version of Windows 10 or Windows 11 with Defender enabled is affected. That’s hundreds of millions of devices. The good news? Microsoft’s patch, rolled out through the regular Windows Update channel on June 11, addresses the issue. Users who keep automatic updates on are already protected.

If you’ve been delaying that restart, now is the time. The RoguePlanet exploit code is public, and while no mass exploitation has been reported yet, the barrier to entry for attackers just dropped to zero.

Why Public PoC Exploits Matter

There’s a long-running debate in the security community: should researchers publish exploit code before a patch exists? Nightmare-Eclipse chose the aggressive route. By releasing the PoC, they forced Microsoft to prioritize the fix. But they also handed a weapon to every script kiddie and criminal group monitoring exploit databases.

This isn’t abstract. In 2023, the average time between a PoC publication and active exploitation in the wild was just 15 days, according to zero-day exploit trends tracked by multiple threat intelligence firms. The RoguePlanet case fits that pattern perfectly.

Microsoft’s response was swift. The company acknowledged the issue, developed a patch, and pushed it out within a week of the disclosure. That’s fast by any standard, especially for a component as complex as the Defender scanning engine.

How to Protect Yourself Now

If you’re running Windows, here’s what to do:

  • Check for updates: Go to Settings > Windows Update > Check for updates. Install any pending patches immediately.
  • Restart your machine: The fix won’t take effect until you reboot. Don’t put it off.
  • Verify Defender is active: Open Windows Security and confirm real-time protection is on. The patch only helps if the service is running.
  • Monitor for unusual behavior: If your system crashes or Defender stops unexpectedly, it could be a sign of attempted exploitation.

For IT administrators, Microsoft has also released a standalone update package through the Microsoft Update Catalog. Enterprise environments with strict patch management cycles should prioritize this one.

The Bigger Picture: Microsoft’s Zero-Day Problem

The RoguePlanet incident is the latest chapter in a recurring story. Microsoft’s security products have been a frequent target for researchers looking to make a name. In the past 18 months, multiple critical flaws have been disclosed in Defender, Exchange Server, and the Windows kernel.

Some of these disclosures follow responsible disclosure protocols — researchers notify Microsoft privately, give 90 days for a fix, then publish. Others, like Nightmare-Eclipse’s approach, are more confrontational. The result is the same: patches get released, but not before the window of risk opens.

Microsoft has tried to incentivize responsible disclosure through its bug bounty program, offering up to $250,000 for critical vulnerabilities. But for some researchers, the publicity and influence that come with a dramatic zero-day drop are worth more than the cash.

What Comes Next

For now, the RoguePlanet threat is contained. The patch is out, and users who update are safe. But the broader tension between researchers and vendors isn’t going away. As long as vulnerabilities exist in core system components, someone will find them — and someone will decide whether to whisper or shout.

Microsoft’s challenge is to make the whisper more attractive than the shout. Until then, keep your system updated and your guard up.

Continue Reading

Trending