Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

2026-05-25T20:51:37Z646e518838f724919d7be5f8155db7340c11d28311230083c41c04cacb73b2ee
AD CSAI extensionAPTActive Directory Certificate ServicesAppDomainManager hijackingCopy FailGremlin stealerIranian APTLinux kernel LPEPAN-OS captive portalRATRCEROADtoolsScreening SerpensTamperedChefbrowser extensioncloud intrusiondata exfiltrationmalvertisingnpm supply chainobfuscationsession hijackingsupply-chaintrojanized appszero-day

What happened

Unit 42 published a set of May 2026 investigations covering active espionage and emergent attack techniques: Iranian APT “Screening Serpens” using AppDomainManager hijacking and new RATs; ROADtools being abused for cloud intrusions; evolving npm supply-chain threats (wormable malware, CI/CD persistence); TamperedChef clusters using trojanized apps and malvertising; Gremlin stealer’s advanced obfuscation, crypto clipping and session hijacking; extensive AD CS (Active Directory Certificate Services) misuse for escalation; exploitation of a PAN-OS captive portal zero-day enabling unauthenticatedR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
646e518838f724919d7be5f8155db7340c11d28311230083c41c04cacb73b2ee
Enrichment time
2026-05-25T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.