Reporting describes two separate Iran-linked espionage efforts. HarfangLab detailed a campaign dubbed RedKitten targeting human-rights NGOs and individuals documenting abuses, using a lure delivered as a Farsi-named 7z archive containing macro-enabled Excel (.xlsm) files. When victims enable the malicious VBA, it drops a C# implant (AppVStreamingUX_Multi_User.dll) via AppDomainManager injection; the operation uses GitHub and Google Drive for configuration/payload retrieval and Telegram for command-and-control, and researchers noted code characteristics consistent with LLM-assisted development.
Separately, Pulsedive research (as summarized) attributed a PowerShell backdoor called TAMECAT to APT42, describing social-engineering via impersonated WhatsApp contacts and links abusing the search-ms URI handler, followed by VBScript-based staging and delivery mechanisms including WebDAV-hosted LNKs disguised as PDFs. TAMECAT was reported to steal credentials from Microsoft Edge and Chrome, establish persistence (e.g., logon scripts and registry run keys), and use multiple C2 channels (including Telegram, Discord, Firebase, and Cloudflare Workers). Other items in the set cover unrelated events: a supply-chain compromise of eScan antivirus update infrastructure distributing a backdoor, and Fortinet’s reporting on Interlock ransomware activity affecting primarily UK/US organizations (not Iran-linked).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
By the end of January 2026, HarfangLab publicly reported the RedKitten campaign and its SloppyMIO implant, highlighting suspected LLM-assisted code generation and the use of GitHub, Google Drive, and Telegram as commoditized infrastructure. The report emphasized targeting of human rights NGOs and individuals documenting abuses.
A separate WhatsApp-delivered phishing operation targeted activists using a fake WhatsApp Web meeting QR flow to hijack accounts and request invasive browser permissions, then presented a fake Gmail login to steal passwords and 2FA codes. Nariman Gharib and TechCrunch said about 50 people were impacted.
Pulsedive researchers disclosed technical details on TAMECAT, a PowerShell-based backdoor used in espionage campaigns attributed to Iran-linked APT42. The malware steals credentials from Microsoft Edge and Chrome, persists via logon scripts and registry run keys, and exfiltrates data over channels including Telegram, Discord, Firebase, Cloudflare Workers, FTP, and HTTPS.
Attackers distributed a Farsi-named 7-Zip archive containing macro-enabled Excel files that purported to list deceased protesters. Enabling the VBA macro triggered AppDomainManager injection to load the SloppyMIO implant, which supports command execution, file theft, persistence, and modular payload delivery via GitHub, Google Drive, and Telegram.
HarfangLab said the RedKitten espionage campaign was first observed in early January 2026, targeting Iranian protesters, NGOs, and activists. The activity was assessed as aligned with Iranian state interests and used lures themed around protester deaths.
Late-2025 unrest and the subsequent crackdown in Iran created the backdrop for cyber operations targeting NGOs, activists, and individuals documenting human rights abuses. Multiple reports tie later malware and phishing activity to this protest period.
The U.S. Treasury sanctioned Iran's Ravin Academy in October 2022, citing its role in supporting MOIS-linked cyber talent development. This action is referenced as background to the broader Iranian cyber-espionage ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.