Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Cyberattack Cripples IT Systems in Middle East

Iran-Linked Cyberattack Cripples IT Systems in Middle East

Posted on June 1, 2026 By CWS

Iran-Linked Cyberattack Cripples IT Systems in Middle East

In recent weeks, a cyberattack attributed to Iran has wreaked havoc on IT systems across the United States and the Middle East. Orchestrated under the guise of the pro-Iranian persona “Ababil of Minab,” the attack went beyond mere data breaches by erasing backups and disabling recovery systems, leaving affected organizations inoperable.

Widespread Disruption Across Multiple Sectors

The cyber onslaught, first detected in late March and early April 2026, saw “Ababil of Minab” claiming responsibility for infiltrating the Los Angeles County Metropolitan Transportation Authority (LA Metro). The breach was officially confirmed on April 2, 2026, following the deletion of virtual machines, which rendered the TAP Mobile App nonfunctional for users.

According to cybersecurity firm Gambit Security, the group behind these attacks is not an independent entity but is linked to Black Shadow, an Iran-affiliated organization suspected of having ties to Iran’s Ministry of Intelligence and Security. Gambit Security’s findings, shared with Cyber Security News, revealed the use of both automated scripts and manual intervention to destroy IT, virtualization, and backup infrastructure.

Coordinated Effort Beyond LA Metro

The cyber campaign extended its reach beyond LA Metro, targeting other significant entities such as the South Florida Regional Transportation Authority, UNIMAC, and the consumer GPS service Vyncs. The attack also impacted sectors in Israel and Turkey, including media, education, and insurance, indicating a calculated and coordinated effort rather than random acts of hacking.

What distinguishes this attack is the systematic approach to eliminating recovery options. The attackers focused on eradicating backup systems, deleting database chains, and removing operating system files to thwart any restoration attempts. In one instance, an AI chatbot was leveraged to refine a custom script for destruction, adding a sophisticated layer to these state-linked cyber activities.

Advanced Methods of Data Destruction and Theft

The attackers employed a dual approach combining scripted automation and manual system manipulation. At LA Metro, they dismantled virtual machines using the agency’s own virtualization platform. At UNIMAC, they erased storage volumes and left behind the “Minab” signature. In a similar vein, at Vyncs, a custom Python script targeted 58 SQL Server databases, successfully eradicating all with no failures. Concurrently, SQL backup files and key Windows system folders were manually deleted to ensure total destruction.

In addition to the destruction, investigators found two custom data theft tools in use. One tool compressed and uploaded stolen files to the victim’s website, retrieving them via an attacker-controlled server. Another tool, FileFiend, scanned for files and transmitted them to a command-and-control server.

Implications and Recommendations for Organizations

The most conclusive link to Black Shadow came via a staging server previously used to target Israeli soldiers with a fake support site in August 2025. Organizations in critical sectors such as infrastructure, transportation, and education are urged to reassess their access controls, backup isolation, and incident response measures in the wake of these attacks.

The breadth and sophistication of this cyberattack underscore the necessity for heightened vigilance and robust cybersecurity measures. As the threat landscape evolves, the ability to respond swiftly and effectively to such coordinated attacks becomes imperative for organizations worldwide.

Cyber Security News Tags:Black Shadow, Cyberattack, Cybersecurity, data destruction, Gambit Security, Hacking, Iran, IT systems, LA Metro, Middle East

Post navigation

Previous Post: Critical Linux Kernel Flaw Endangers Systems with Root Access
Next Post: Evolving Beyond vCISO: The Rise of Security Growth Platforms

Related Posts

Microsoft 365 Exchange Online Outage Blocks Email on Outlook Mobile App Microsoft 365 Exchange Online Outage Blocks Email on Outlook Mobile App Cyber Security News
Enhance SOC Visibility to Reduce MTTR Effectively Enhance SOC Visibility to Reduce MTTR Effectively Cyber Security News
New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data Cyber Security News
SecurityMetrics Wins “Data Leak Detection Solution of the Year” at the 2025 CyberSecurity Breakthrough Awards SecurityMetrics Wins “Data Leak Detection Solution of the Year” at the 2025 CyberSecurity Breakthrough Awards Cyber Security News
Linux UDisks daemon Vulnerability Let Attackers Gaining Access to Files Owned by Privileged Users Linux UDisks daemon Vulnerability Let Attackers Gaining Access to Files Owned by Privileged Users Cyber Security News
NAKIVO v11.2 Enhances Replication and vSphere Support NAKIVO v11.2 Enhances Replication and vSphere Support Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • File Access Restored for Microsoft Office Web Users
  • Exploited Windows Netlogon Flaw Demands Urgent Patch
  • Cyber Espionage Campaign Targets Czech Republic and Taiwan
  • Critical Plesk Flaw Allows Command Execution on Servers
  • New Flaws and AI Threats Shape Cybersecurity Landscape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • File Access Restored for Microsoft Office Web Users
  • Exploited Windows Netlogon Flaw Demands Urgent Patch
  • Cyber Espionage Campaign Targets Czech Republic and Taiwan
  • Critical Plesk Flaw Allows Command Execution on Servers
  • New Flaws and AI Threats Shape Cybersecurity Landscape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark