Rapid7 Detection Coverage for Iran-Linked Cyber Activity
2026-03-12T07:23:44Z•ec706814e2ca0a42816c58f0dd6a0120e496a6fa76e222753cf81732930e26ef
aptattack-surface-managementclickfixcredential-theftddosdetectiondigital-wallet-theftelevation-of-privilegeexposure-managementhacktivistintelligence-hubiran-linkednation-statepatch-tuesdayphishingpurple-teamingrapid7sql-serverstealerweb-injectionwebsite-defacementwordpress-compromise
What happened
Collection of Rapid7 blog posts (Mar 2026) summarizing elevated Iran-linked cyber activity, detection coverage, and multiple research and product updates. Rapid7 documents increased hacktivist and state-linked activity (phishing, DDoS, website defacements, reconnaissance) and is publishing related IOCs in its Intelligence Hub. Rapid7 Labs also details a widespread WordPress compromise (active since Dec 2025) that injects a ClickFix implant disguised as a Cloudflare CAPTCHA to deliver an in-memory multi-stage stealer targeting credentials and crypto wallets across >250 legitimate sites in ~12+
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- ec706814e2ca0a42816c58f0dd6a0120e496a6fa76e222753cf81732930e26ef
- Enrichment time
- 2026-03-12T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.