Pro-Iranian Nasir Security is targeting energy companies in the Gulf

2026-03-23T14:51:47Z2f59b41aa4cfc68d005e75654696fd19fed797eb8f91d694645c634076f63672
Aqua SecurityCISA-KEVDocker HubIran-linkedOracle Identity ManagerRussia-linkedTelegram C2TrivyWorldLeaksdark webenergy sectorinfostealernation-statephishingransomwaresupply-chain

What happened

Multiple high-impact incidents reported: Resecurity tracks Iran-linked Nasir Security targeting energy companies in the Gulf; researchers disclosed a supply-chain compromise of Trivy images on Docker Hub (malicious TeamPCP infostealer) that defaced 44 Aqua Security repositories and exposed developers; FBI warns Iran-linked actors are using Telegram as C2 to deploy malware against dissidents and journalists; Russia-linked actors conduct phishing campaigns to hijack WhatsApp and Signal accounts of officials and journalists; international law enforcement’s Operation Alice took down ~373,000 fake/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2f59b41aa4cfc68d005e75654696fd19fed797eb8f91d694645c634076f63672
Enrichment time
2026-03-23T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Pro-Iranian Nasir Security is targeting energy companies in the Gulf · Baitaphish