Tag

Unit 42

All articles tagged with #unit 42

Iran Cyber Escalation Intensifies as Connectivity Fails and Hacktivists Rise
technology1 month ago

Iran Cyber Escalation Intensifies as Connectivity Fails and Hacktivists Rise

Following Feb 28, 2026 U.S.–Israel strikes, Iran’s cyber posture shifts amid severe internet outages that likely constrain state-aligned actors, while hacktivist groups and other threat actors expand globally with low-to-medium impact activities (DDoS, data leaks, phishing). Unit 42 observes active phishing via a malicious Android app and notes a surge in cyber activism tied to an “Electronic Operations Room.” Defensive guidance emphasizes offline backups, out-of-band verification, patching internet-facing assets, phishing awareness, IP geofencing, and robust incident response; multi-layer defense and ongoing updates from cyber authorities are advised as activity remains fluid.

Asia-based cyberespionage campaign breaches governments worldwide and expands reconnaissance
technology2 months ago

Asia-based cyberespionage campaign breaches governments worldwide and expands reconnaissance

Palo Alto Networks Unit 42 reports an Asia-based cyberespionage group compromised at least 70 institutions across 37 governments and conducted reconnaissance in 155 countries. The attackers used phishing to drop a Cobalt Strike payload and a mix of exploits to gain footholds, with some victims accessed for months (including a parliament and key ministries). The operation is described as potentially the most widespread state-sponsored government breach since SolarWinds, with the group adapting to different targets and events and attribution to a specific country not determined.