Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Home/Threats/Iran-Linked Hackers Wipe Middle East Orgs’ IT, Backups, and Recovery Systems
Threats

Iran-Linked Hackers Wipe Middle East Orgs’ IT, Backups, and Recovery Systems

Key Takeaways An Iran-linked threat actor, operating under the “Ababil of Minab” persona, has launched a destructive cyber campaign targeting organizations in the U.S., Middle East, and...

David kimber
David kimber
June 1, 2026 5 Min Read
49 0

Key Takeaways

  • An Iran-linked threat actor, operating under the “Ababil of Minab” persona, has launched a destructive cyber campaign targeting organizations in the U.S., Middle East, and Turkey.
  • The attacks prioritize data destruction, systematically wiping IT systems, critical backups, and recovery infrastructure, rather than mere data theft.
  • Victims include major transportation authorities, a manufacturing company, and a consumer GPS tracking service, with additional targets in media, higher education, and insurance sectors.
  • Forensic analysis links “Ababil of Minab” to the notorious Black Shadow group, which is attributed to Iran’s Ministry of Intelligence and Security.

A sophisticated and highly destructive cyber campaign, attributed to an Iran-linked threat actor operating under the guise of “Ababil of Minab,” has systematically targeted and crippled IT systems across multiple organizations in the United States, the Middle East, and Turkey. This operation goes far beyond typical data exfiltration, focusing instead on the complete annihilation of digital infrastructure, including primary systems, backups, and crucial recovery mechanisms.

Table Of Content

  • Key Takeaways
  • Attribution to Iran’s Black Shadow Group
  • Widespread Impact Across Sectors
  • Execution of Destruction
  • Custom Tools and Attribution Details
  • Indicators of Compromise (IoCs)
  • What You Should Do

The campaign, which first emerged in late March and early April 2026, saw “Ababil of Minab” claim responsibility for a breach against the Los Angeles County Metropolitan Transportation Authority (LA Metro). This incident involved the destruction of data, confirmed by LA Metro on April 2, 2026. Following the deletion of virtual machines from the agency’s management console, riders reported issues with the TAP Mobile App, unable to load fare.

Attribution to Iran’s Black Shadow Group

Analysts at Gambit Security have concluded that “Ababil of Minab” is not an independent hacktivist collective, despite its claims. Forensic evidence strongly connects the persona to Black Shadow, a known Iran-linked group. The Israel National Cyber Directorate has previously attributed Black Shadow to Iran’s Ministry of Intelligence and Security, reinforcing the state-sponsored nature of these destructive attacks.

According to a report by Gambit Security, the attackers employed a combination of scripted automation and direct, “hands-on keyboard” techniques to dismantle IT, virtualization, and backup infrastructure. This dual approach allowed for both widespread damage and precise targeting of critical recovery points.

Widespread Impact Across Sectors

Beyond LA Metro, the destructive campaign impacted several other entities. The South Florida Regional Transportation Authority experienced similar attacks, as did the company UNIMAC and the consumer GPS tracking service Vyncs. Investigators also identified victims in Israel and Turkey, spanning the media, higher education, and insurance sectors. The broad scope of these attacks suggests a meticulously planned and coordinated effort, rather than isolated opportunistic incidents.

A defining characteristic of this campaign is the attackers’ methodical approach to eliminating any possibility of recovery. They actively sought out backup systems, executed commands to drop entire database chains, and deleted operating system files to prevent system restoration. In one particularly alarming incident, the threat actor utilized an AI chatbot to refine a custom destruction script, highlighting an evolving sophistication in state-linked cyber operations.

Execution of Destruction

The attackers leveraged two primary methods for their destructive operations: automated scripts and direct manual intervention. At LA Metro, they gained access to the virtualization platform, then powered off and deleted virtual machines. At UNIMAC, they wiped three storage volumes, notably renaming new partitions “Minab” as a defiant signature.

For Vyncs, a custom Python script named main.py was deployed, iterating through 58 SQL Server targets to drop every database. This script achieved a 100% success rate. Concurrently, the attacker manually deleted 16 daily SQL backup files and subsequently destroyed core Windows system folders via Windows Explorer, effectively crashing their own remote session and confirming the complete eradication of data.

The South Florida Regional Transportation Authority was compromised through a proxied remote desktop connection. Once inside, the attackers took databases offline and used a secure deletion tool to overwrite the web hosting directory, including a dedicated SQL backup folder. These actions demonstrate a deep understanding of victim environments and a clear intent to ensure irrecoverable data loss.

Custom Tools and Attribution Details

During their investigation, researchers uncovered two custom tools used for data exfiltration. The first method involved compressing stolen files and uploading them to the victim’s own public website, then retrieving them via an attacker-controlled server. The second was a bespoke C++ tool named FileFiend, designed to scan local drives and network shares before transmitting stolen data to a hardcoded command-and-control server.

The attackers also deployed a Flask-based file receiver to collect uploads from compromised environments. While file transfers were encrypted, the encryption key was transmitted within the same request as the data, rendering it vulnerable to interception. Intriguingly, attempts to access non-existent pages on the attacker’s server would redirect visitors to the FBI’s official website.

The most compelling evidence linking “Ababil of Minab” to Black Shadow emerged from a staging server. This server had previously hosted a fake mental health support website in August 2025, specifically designed to target Israeli soldiers—an operation definitively attributed to Black Shadow. The same server was later observed transferring stolen files into the infrastructure used for the current destructive campaign, solidifying the attribution.

Indicators of Compromise (IoCs)

Type Indicator Description
IPv4 31.172.87.20 Operator staging server; served TLS for nefeshhope[.]com
IPv4 212.83.61.213 FileFiend C2, hardcoded in 81a2535
IPv4 66.85.26.183 FileFiend C2, hardcoded in c8cc422 and 33a6b49
IPv4 195.20.17.129 FileFiend C2, hardcoded in d76a943
IPv4 46.246.125.131 Source IP of propaganda site
IPv4 146.70.233.83 Served TLS for nefeshhope[.]com
IPv4 91.193.19.198 Attacker-controlled exit node
IPv4 89.36.231.56 Served TLS for feedback.nefeshhope[.]com
IPv4 84.200.89.52 Served TLS for nefeshhope[.]com
IPv4 46.30.190.173 Served TLS for members.nefeshhope[.]com
Domain nefeshhope[.]com Operator-controlled site
Domain members.nefeshhope[.]com Observed communicating with A.ExE Go tunneler
Domain banujcobaar[.]com Redirected nefeshhope[.]com
SHA-256 81a25357d027d0f04a43139377d5d58384b8e9b0770e699cdcc37e600641cf90 FileFiend / Exchangedb.exe
SHA-256 c8cc4225d1e21324ef419adbb1c10dd0578fb034b5f5d7b8000f0aae1871c061 FileFiend / Exchangedb.exe
SHA-256 33a6b4900c2fbfb3c2d816947871eade800d0c0e2a2680871700fd6e640e5f20 FileFiend / Exchangedb.exe
SHA-256 d76a94309240a7e2f11a89fab54a6853628e976a5ff19084b1b0894c89e6a742 FileFiend
SHA-256 f6db77be038980e9dbbf9f11e0f7ae7d2d4d3f1a53199958f1f55137dde5efd3 A.ExE Go tunneler communicating with members.nefeshhope[.]com
SHA-256 1c699720034367ba9761a8d31c854fd444e8e3c8c31c520a39c543cf95286029 Go tunneler; served from 45.150.108.61
SHA-256 38965a60835a5ee3eaefd3d0bffa97c0e4f0c5cd74d31d8053bedeea14f536ee Go tunneler; served from 45.150.108.61
File Path C:UserscasioDesktopuploader v3temp uploader v3temp uploader v3.cpp Developer source path in FileFiend
File Path F:OH~FileFiend(Uploader)uploader v3x64Releasetemp uploader v3.pdb PDB path in FileFiend v4
Filename Exchangedb.exe Decoy filename for FileFiend uploader
TLS Subject O=Acme Cloud Solutions Inc, CN=localhost, [email protected] Self-signed certificate on Flask receiver
Tool proxychains Used for proxied RDP and download tunneling
Tool xfreerdp Used for proxied RDP access
Tool axel Linux CLI download accelerator used in exfiltration
Tool http.flask.py Custom Flask receiver
Tool WipeFile Windows utility for secure file deletion

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Isolate Backups: Implement robust offline or immutable backup solutions that are physically or logically separated from the primary network to prevent their destruction during an attack.
  • Strengthen Access Controls: Enforce multi-factor authentication (MFA) across all critical systems and accounts, particularly for remote access and administrative interfaces. Regularly review and audit access privileges.
  • Implement Network Segmentation: Segment networks to limit lateral movement by attackers. Critical infrastructure and sensitive data should reside in highly restricted network zones.
  • Enhance Monitoring and Detection: Deploy advanced endpoint detection and response (EDR) and security information and event management (SIEM) solutions to detect unusual activity, especially attempts to delete or modify system files and backups.
  • Develop and Test Incident Response Plans: Regularly update and practice incident response and disaster recovery plans, focusing on scenarios involving data destruction and system wiping.
  • Regularly Patch and Update: Ensure all operating systems, applications, and firmware are kept up-to-date with the latest security patches to mitigate known vulnerabilities.
  • Educate Employees: Conduct ongoing cybersecurity awareness training to help employees recognize and report phishing attempts and other social engineering tactics that could lead to initial compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

DriveSurge Threat Actor Exploits ClickFix and Fake Updates to Infect Websites

Next Post

Critical Plesk Vulnerability Lets Users Execute Arbitrary Commands

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us