Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran (Updated March 26)
2026-03-31T08:51:35Z•700bff09da2d71008eefd657686851c9ce10b72846a39613d4cea3ece3b07ce7
ai agents securityai in malwareboggy serpenscl-unk-1068credential theftespionagehandala hackidentity weaponizationiranian cyber activitymicrosoft intune abusephishingprompt fuzzingprompt injectionransom/rat/loadersrecruitment fraudsoutheast asia targetingunit42usbfectvoid manticorewiper malware
What happened
Unit 42’s March 2026 briefings describe an escalation in Iranian-linked offensive activity (including wipers and identity-weaponization), continued refinement of espionage operations against Southeast Asian government and military targets (USBFect, custom backdoors, RATs and loaders), and an increase in phishing and recruitment scams impersonating legitimate organizations. Notable topics: Boggy Serpens and Handala Hack (aka Void Manticore) wiper activity and Microsoft Intune abuse; a multi-cluster espionage campaign against a Southeast Asian government; long-running CL-UNK-1068 operations; and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 700bff09da2d71008eefd657686851c9ce10b72846a39613d4cea3ece3b07ce7
- Enrichment time
- 2026-03-31T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.