Adversary Intelligence — 2026-05-23
Iranian Hackers Target US Aviation and Oil Gas Companies in Sustained Espionage Campaign
BLUFIran's pivot to covert access against deep-access engineering targets prioritizes durable espionage over disruption, making a publicly attributed breach at a named firm unlikely before year's end.
Palo Alto Networks' Unit 42 reported Friday that Screening Serpens, also tracked as UNC1549 and Smoke Sandstorm, used fake job postings and malware-laden video conferencing software to target software engineers at US aviation and oil and gas firms, plus organizations in Israel and the UAE 12. In at least one case the operatives impersonated a US airline; one fake posting appeared to be AI-generated, Unit 42 said 12. The campaign, which Unit 42 traces to mid-February 2026, involved six new RAT variants deployed via AppDomainManager hijacking, a technique that manipulates .NET application initialization to disable targets' own security mechanisms 1. Unit 42 told CNN it has no evidence any of those firms were successfully breached, though it believes other unnamed targets in the campaign were compromised 12. The group has maintained high operational tempo with "no signs of slowing down" despite the war and a March IDF strike on what Israel described as Iran's "Cyber Warfare headquarters," Unit 42 said 12.
AnalysisTehran's priority on engineering-level access signals an emphasis on durable covert collection over disruptive operations, consistent with constrained conventional strike options against the US mainland. A publicly attributed intrusion at a named firm is
unlikely by December 31, 2026. Low confidence in that assessment reflects Unit 42's reliance on commercial telemetry without corroborating signals intelligence or government attribution. The engineering-access posture itself further depresses the probability of the visible incident that typically triggers public attribution. The campaign's restraint may reflect deliberate escalation management rather than incapacity, preserving more aggressive options for a future confrontation window. Without a confirmed breach, voluntary information-sharing remains the primary defensive mechanism and pressure for mandatory CISA emergency directives stays muted.
3 sources
- Iranian hackers are targeting aviation, oil and gas companies in espionage scheme, researchers say - CNN via KRDO
- Iranian hackers are targeting aviation, oil and gas companies in espionage scheme, researchers say - CNN
- Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns - Palo Alto Networks Unit 42
View in full brief →