Rapid7 Detection Coverage for Iran-Linked Cyber Activity

2026-03-12T07:23:44Zec706814e2ca0a42816c58f0dd6a0120e496a6fa76e222753cf81732930e26ef
aptattack-surface-managementclickfixcredential-theftddosdetectiondigital-wallet-theftelevation-of-privilegeexposure-managementhacktivistintelligence-hubiran-linkednation-statepatch-tuesdayphishingpurple-teamingrapid7sql-serverstealerweb-injectionwebsite-defacementwordpress-compromise

What happened

Collection of Rapid7 blog posts (Mar 2026) summarizing elevated Iran-linked cyber activity, detection coverage, and multiple research and product updates. Rapid7 documents increased hacktivist and state-linked activity (phishing, DDoS, website defacements, reconnaissance) and is publishing related IOCs in its Intelligence Hub. Rapid7 Labs also details a widespread WordPress compromise (active since Dec 2025) that injects a ClickFix implant disguised as a Cloudflare CAPTCHA to deliver an in-memory multi-stage stealer targeting credentials and crypto wallets across >250 legitimate sites in ~12+

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
ec706814e2ca0a42816c58f0dd6a0120e496a6fa76e222753cf81732930e26ef
Enrichment time
2026-03-12T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.