Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

2026-05-26T20:51:40Z3fd544e1f24b05667691acec819847e0999747cd532d3c3fd838f30d7c87a9f7
AD CS exploitationAI browser extensionsAPTActive Directory Certificate ServicesAirSnitch Wi‑Fi attacks`,`autonomous AI attacks`,`detection-besAppDomainManager hijackCI/CD persistenceCVE-2026-0300CVE-2026-31431Copy FailGremlin StealerLinux kernel LPEPAN-OSRATROADtoolsScreening SerpensTamperedChefcloud intrusionmalvertisingnpm supply chainobfuscationsession hijackingsupply-chaintrojanized appswormable malware

What happened

Unit 42 published multiple high-priority research posts covering active nation-state and criminal activity, supply-chain and cloud threats, advanced exploitation techniques, and new high-impact vulnerabilities. Highlights include: Screening Serpens’ 2026 campaigns using AppDomainManager hijacking and new RAT variants against tech and defense targets; misuse of the open-source ROADtools framework for cloud intrusions; evolving npm supply-chain threats (wormable malware, CI/CD persistence, multi-stage attacks); TamperedChef clusters using trojanized apps and malvertising with certificate/code re

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
3fd544e1f24b05667691acec819847e0999747cd532d3c3fd838f30d7c87a9f7
Enrichment time
2026-05-26T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.