Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
2026-05-22T20:51:46Z•9b9e34774853bd04818846b7289d1a5080a4964e72e3e5129f3be9b005e86c58
AD CS exploitationAPTActive Directory Certificate ServicesAppDomainManager hijackingCVE-2026-0300CVE-2026-31431Copy FailGremlin stealerIranian APTLPE (local privilege escalation)`,`zero-day`,`unauthenticated RLinux kernelPAN-OSRATROADtoolsScreening SerpensTamperedChefcaptive portalcloud intrusionmalvertisingnpm supply chainobfuscationsession hijackingstealersupply-chaintrojanized apps
What happened
A Unit 42 digest covering multiple active threats and research findings (May 2026). Highlights include: Iranian APT “Screening Serpens” using AppDomainManager hijacking and new RATs to target tech and defense; misuse of the open-source ROADtools framework for cloud intrusions; evolving npm supply‑chain threats including wormable malware and CI/CD persistence; TamperedChef clusters delivered via trojanized apps and malvertising; an evolved Gremlin stealer using advanced obfuscation and session hijacking; advanced AD CS (Active Directory Certificate Services) misuse for privilege escalation; a 0
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 9b9e34774853bd04818846b7289d1a5080a4964e72e3e5129f3be9b005e86c58
- Enrichment time
- 2026-05-22T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.