Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran (Updated March 26)

2026-03-31T08:51:35Z700bff09da2d71008eefd657686851c9ce10b72846a39613d4cea3ece3b07ce7
ai agents securityai in malwareboggy serpenscl-unk-1068credential theftespionagehandala hackidentity weaponizationiranian cyber activitymicrosoft intune abusephishingprompt fuzzingprompt injectionransom/rat/loadersrecruitment fraudsoutheast asia targetingunit42usbfectvoid manticorewiper malware

What happened

Unit 42’s March 2026 briefings describe an escalation in Iranian-linked offensive activity (including wipers and identity-weaponization), continued refinement of espionage operations against Southeast Asian government and military targets (USBFect, custom backdoors, RATs and loaders), and an increase in phishing and recruitment scams impersonating legitimate organizations. Notable topics: Boggy Serpens and Handala Hack (aka Void Manticore) wiper activity and Microsoft Intune abuse; a multi-cluster espionage campaign against a Southeast Asian government; long-running CL-UNK-1068 operations; and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
700bff09da2d71008eefd657686851c9ce10b72846a39613d4cea3ece3b07ce7
Enrichment time
2026-03-31T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.