Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Researchers have identified infrastructure belonging to an Iran-linked hacking group spread across multiple European and Middle Eastern locations, suggesting an expanded operational footprint in these regions. The discovery of servers and domains associated with the group indicates a potentially wider targeting scope than previously understood for this threat actor.
The FBI has disrupted Chinese proxy tools that were used in a widespread hacking campaign targeting multiple U.S. government agencies and infrastructure, including NASA, the Federal Reserve, the US Senate, and the Justice Department. According to the Department of Justice, the compromises affected critical institutions across the federal government, highlighting the scope and sophistication of the operation.
The FBI and Department of Justice disrupted two hacking platforms, QScan and QTRouter, operated by Chinese state-sponsored group QTFY to target U.S. critical infrastructure and sensitive networks. The infrastructure was attributed to actors working for Nanjing Xinjiuwei Network Technology Company, a Chinese entity involved in the data theft operations.
US law enforcement disrupted Chinese state-backed hacking tools that were being used to scan, infect, and exploit IoT devices in targeted attacks against federal agencies including the Federal Reserve, Department of Justice, and Senate. The operation represents a significant enforcement action against state-sponsored cyber infrastructure designed to compromise both government and critical infrastructure targets across multiple sectors.
Researchers at Group-IB have identified new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored group affiliated with the IRGC, including a TWOSTROKE-like backdoor and SSH tunneler. The analysis ranks Nimbus Manticore among the most active Iranian APT groups operating in 2026.