Iran-Linked Hackers Wipe Middle East Orgs’ IT, Backups, and Recovery Systems
Key Takeaways An Iran-linked threat actor, operating under the “Ababil of Minab” persona, has launched a destructive cyber campaign targeting organizations in the U.S., Middle East, and...
Key Takeaways
- An Iran-linked threat actor, operating under the “Ababil of Minab” persona, has launched a destructive cyber campaign targeting organizations in the U.S., Middle East, and Turkey.
- The attacks prioritize data destruction, systematically wiping IT systems, critical backups, and recovery infrastructure, rather than mere data theft.
- Victims include major transportation authorities, a manufacturing company, and a consumer GPS tracking service, with additional targets in media, higher education, and insurance sectors.
- Forensic analysis links “Ababil of Minab” to the notorious Black Shadow group, which is attributed to Iran’s Ministry of Intelligence and Security.
A sophisticated and highly destructive cyber campaign, attributed to an Iran-linked threat actor operating under the guise of “Ababil of Minab,” has systematically targeted and crippled IT systems across multiple organizations in the United States, the Middle East, and Turkey. This operation goes far beyond typical data exfiltration, focusing instead on the complete annihilation of digital infrastructure, including primary systems, backups, and crucial recovery mechanisms.
Table Of Content
The campaign, which first emerged in late March and early April 2026, saw “Ababil of Minab” claim responsibility for a breach against the Los Angeles County Metropolitan Transportation Authority (LA Metro). This incident involved the destruction of data, confirmed by LA Metro on April 2, 2026. Following the deletion of virtual machines from the agency’s management console, riders reported issues with the TAP Mobile App, unable to load fare.
Attribution to Iran’s Black Shadow Group
Analysts at Gambit Security have concluded that “Ababil of Minab” is not an independent hacktivist collective, despite its claims. Forensic evidence strongly connects the persona to Black Shadow, a known Iran-linked group. The Israel National Cyber Directorate has previously attributed Black Shadow to Iran’s Ministry of Intelligence and Security, reinforcing the state-sponsored nature of these destructive attacks.
According to a report by Gambit Security, the attackers employed a combination of scripted automation and direct, “hands-on keyboard” techniques to dismantle IT, virtualization, and backup infrastructure. This dual approach allowed for both widespread damage and precise targeting of critical recovery points.
Widespread Impact Across Sectors
Beyond LA Metro, the destructive campaign impacted several other entities. The South Florida Regional Transportation Authority experienced similar attacks, as did the company UNIMAC and the consumer GPS tracking service Vyncs. Investigators also identified victims in Israel and Turkey, spanning the media, higher education, and insurance sectors. The broad scope of these attacks suggests a meticulously planned and coordinated effort, rather than isolated opportunistic incidents.
A defining characteristic of this campaign is the attackers’ methodical approach to eliminating any possibility of recovery. They actively sought out backup systems, executed commands to drop entire database chains, and deleted operating system files to prevent system restoration. In one particularly alarming incident, the threat actor utilized an AI chatbot to refine a custom destruction script, highlighting an evolving sophistication in state-linked cyber operations.
Execution of Destruction
The attackers leveraged two primary methods for their destructive operations: automated scripts and direct manual intervention. At LA Metro, they gained access to the virtualization platform, then powered off and deleted virtual machines. At UNIMAC, they wiped three storage volumes, notably renaming new partitions “Minab” as a defiant signature.
For Vyncs, a custom Python script named main.py was deployed, iterating through 58 SQL Server targets to drop every database. This script achieved a 100% success rate. Concurrently, the attacker manually deleted 16 daily SQL backup files and subsequently destroyed core Windows system folders via Windows Explorer, effectively crashing their own remote session and confirming the complete eradication of data.
The South Florida Regional Transportation Authority was compromised through a proxied remote desktop connection. Once inside, the attackers took databases offline and used a secure deletion tool to overwrite the web hosting directory, including a dedicated SQL backup folder. These actions demonstrate a deep understanding of victim environments and a clear intent to ensure irrecoverable data loss.
Custom Tools and Attribution Details
During their investigation, researchers uncovered two custom tools used for data exfiltration. The first method involved compressing stolen files and uploading them to the victim’s own public website, then retrieving them via an attacker-controlled server. The second was a bespoke C++ tool named FileFiend, designed to scan local drives and network shares before transmitting stolen data to a hardcoded command-and-control server.
The attackers also deployed a Flask-based file receiver to collect uploads from compromised environments. While file transfers were encrypted, the encryption key was transmitted within the same request as the data, rendering it vulnerable to interception. Intriguingly, attempts to access non-existent pages on the attacker’s server would redirect visitors to the FBI’s official website.
The most compelling evidence linking “Ababil of Minab” to Black Shadow emerged from a staging server. This server had previously hosted a fake mental health support website in August 2025, specifically designed to target Israeli soldiers—an operation definitively attributed to Black Shadow. The same server was later observed transferring stolen files into the infrastructure used for the current destructive campaign, solidifying the attribution.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| IPv4 | 31.172.87.20 | Operator staging server; served TLS for nefeshhope[.]com |
| IPv4 | 212.83.61.213 | FileFiend C2, hardcoded in 81a2535 |
| IPv4 | 66.85.26.183 | FileFiend C2, hardcoded in c8cc422 and 33a6b49 |
| IPv4 | 195.20.17.129 | FileFiend C2, hardcoded in d76a943 |
| IPv4 | 46.246.125.131 | Source IP of propaganda site |
| IPv4 | 146.70.233.83 | Served TLS for nefeshhope[.]com |
| IPv4 | 91.193.19.198 | Attacker-controlled exit node |
| IPv4 | 89.36.231.56 | Served TLS for feedback.nefeshhope[.]com |
| IPv4 | 84.200.89.52 | Served TLS for nefeshhope[.]com |
| IPv4 | 46.30.190.173 | Served TLS for members.nefeshhope[.]com |
| Domain | nefeshhope[.]com | Operator-controlled site |
| Domain | members.nefeshhope[.]com | Observed communicating with A.ExE Go tunneler |
| Domain | banujcobaar[.]com | Redirected nefeshhope[.]com |
| SHA-256 | 81a25357d027d0f04a43139377d5d58384b8e9b0770e699cdcc37e600641cf90 | FileFiend / Exchangedb.exe |
| SHA-256 | c8cc4225d1e21324ef419adbb1c10dd0578fb034b5f5d7b8000f0aae1871c061 | FileFiend / Exchangedb.exe |
| SHA-256 | 33a6b4900c2fbfb3c2d816947871eade800d0c0e2a2680871700fd6e640e5f20 | FileFiend / Exchangedb.exe |
| SHA-256 | d76a94309240a7e2f11a89fab54a6853628e976a5ff19084b1b0894c89e6a742 | FileFiend |
| SHA-256 | f6db77be038980e9dbbf9f11e0f7ae7d2d4d3f1a53199958f1f55137dde5efd3 | A.ExE Go tunneler communicating with members.nefeshhope[.]com |
| SHA-256 | 1c699720034367ba9761a8d31c854fd444e8e3c8c31c520a39c543cf95286029 | Go tunneler; served from 45.150.108.61 |
| SHA-256 | 38965a60835a5ee3eaefd3d0bffa97c0e4f0c5cd74d31d8053bedeea14f536ee | Go tunneler; served from 45.150.108.61 |
| File Path | C:UserscasioDesktopuploader v3temp uploader v3temp uploader v3.cpp | Developer source path in FileFiend |
| File Path | F:OH~FileFiend(Uploader)uploader v3x64Releasetemp uploader v3.pdb | PDB path in FileFiend v4 |
| Filename | Exchangedb.exe | Decoy filename for FileFiend uploader |
| TLS Subject | O=Acme Cloud Solutions Inc, CN=localhost, [email protected] | Self-signed certificate on Flask receiver |
| Tool | proxychains | Used for proxied RDP and download tunneling |
| Tool | xfreerdp | Used for proxied RDP access |
| Tool | axel | Linux CLI download accelerator used in exfiltration |
| Tool | http.flask.py | Custom Flask receiver |
| Tool | WipeFile | Windows utility for secure file deletion |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Isolate Backups: Implement robust offline or immutable backup solutions that are physically or logically separated from the primary network to prevent their destruction during an attack.
- Strengthen Access Controls: Enforce multi-factor authentication (MFA) across all critical systems and accounts, particularly for remote access and administrative interfaces. Regularly review and audit access privileges.
- Implement Network Segmentation: Segment networks to limit lateral movement by attackers. Critical infrastructure and sensitive data should reside in highly restricted network zones.
- Enhance Monitoring and Detection: Deploy advanced endpoint detection and response (EDR) and security information and event management (SIEM) solutions to detect unusual activity, especially attempts to delete or modify system files and backups.
- Develop and Test Incident Response Plans: Regularly update and practice incident response and disaster recovery plans, focusing on scenarios involving data destruction and system wiping.
- Regularly Patch and Update: Ensure all operating systems, applications, and firmware are kept up-to-date with the latest security patches to mitigate known vulnerabilities.
- Educate Employees: Conduct ongoing cybersecurity awareness training to help employees recognize and report phishing attempts and other social engineering tactics that could lead to initial compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.