Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets

2026-04-08T08:52:16Z31d0eebd28de88e3ea80292e24b228566d7d2e2f35d7cf55ce1e8033401b4159
AI-prompt-injectionAPT28AiTM-phishingCVE-2025-53521CVE-2026-3055Citrix-NetScalerF5-BIG-IPFortiClient-EMSGPUBreachGrafanaGhostIran-backed-actorsOT-securityTeamPCPVenom-Stealercredential-theftcritical-infrastructuredata-exfiltrationinfostealer-RATsmalicious-dnsphishingprivilege-escalationrouter-hijackrowhammersupply-chainzero-day

What happened

Infosecurity Magazine roundup: Multiple high-impact campaigns and active exploits were reported — Iran-backed threat actors targeted US critical national infrastructure via internet-facing OT assets causing disruption and loss; APT28 hijacked routers/modified VPSs to run malicious DNS servers and steal credentials; and a GPU Rowhammer technique (GPUBreach) enables full system privilege escalation. Researchers disclosed several malware-as-a-service and supply‑chain threats (Venom Stealer, Phantom, DeepLoad, TeamPCP) and novel covert channels (GitHub C2, EtherRAT smart‑contract C2). Vendors and,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
31d0eebd28de88e3ea80292e24b228566d7d2e2f35d7cf55ce1e8033401b4159
Enrichment time
2026-04-08T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets · Baitaphish