Iranian cyber spies target aviation, fintech developers with new malware
Kaspersky identifies NodeRabbit, a new malware family deployed by Iranian APT operators against aviation and fintech developers—European firms in those sectors should review exposure to similar social-engineering vectors.
Summary written by editorial AI · Source link below
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
Editorial Analysis
European aviation and fintech firms operate in sectors actively targeted by Iranian state-sponsored groups; the emergence of new custom malware families signals persistent and evolving campaign investment.
Conduct a targeted threat hunt for NodeRabbit indicators across developer endpoints in aviation and financial technology business units.
Iranian state hackers are deploying new malware against aviation and fintech developers, sectors with significant European exposure.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at The Record in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d