Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
2026-05-26T20:51:40Z•3fd544e1f24b05667691acec819847e0999747cd532d3c3fd838f30d7c87a9f7
AD CS exploitationAI browser extensionsAPTActive Directory Certificate ServicesAirSnitch Wi‑Fi attacks`,`autonomous AI attacks`,`detection-besAppDomainManager hijackCI/CD persistenceCVE-2026-0300CVE-2026-31431Copy FailGremlin StealerLinux kernel LPEPAN-OSRATROADtoolsScreening SerpensTamperedChefcloud intrusionmalvertisingnpm supply chainobfuscationsession hijackingsupply-chaintrojanized appswormable malware
What happened
Unit 42 published multiple high-priority research posts covering active nation-state and criminal activity, supply-chain and cloud threats, advanced exploitation techniques, and new high-impact vulnerabilities. Highlights include: Screening Serpens’ 2026 campaigns using AppDomainManager hijacking and new RAT variants against tech and defense targets; misuse of the open-source ROADtools framework for cloud intrusions; evolving npm supply-chain threats (wormable malware, CI/CD persistence, multi-stage attacks); TamperedChef clusters using trojanized apps and malvertising with certificate/code re
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 3fd544e1f24b05667691acec819847e0999747cd532d3c3fd838f30d7c87a9f7
- Enrichment time
- 2026-05-26T20:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.