Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Cyberattack Cripples IT Systems in Middle East

Iran-Linked Cyberattack Cripples IT Systems in Middle East

Posted on June 1, 2026 By CWS

Iran-Linked Cyberattack Cripples IT Systems in Middle East

In recent weeks, a cyberattack attributed to Iran has wreaked havoc on IT systems across the United States and the Middle East. Orchestrated under the guise of the pro-Iranian persona “Ababil of Minab,” the attack went beyond mere data breaches by erasing backups and disabling recovery systems, leaving affected organizations inoperable.

Widespread Disruption Across Multiple Sectors

The cyber onslaught, first detected in late March and early April 2026, saw “Ababil of Minab” claiming responsibility for infiltrating the Los Angeles County Metropolitan Transportation Authority (LA Metro). The breach was officially confirmed on April 2, 2026, following the deletion of virtual machines, which rendered the TAP Mobile App nonfunctional for users.

According to cybersecurity firm Gambit Security, the group behind these attacks is not an independent entity but is linked to Black Shadow, an Iran-affiliated organization suspected of having ties to Iran’s Ministry of Intelligence and Security. Gambit Security’s findings, shared with Cyber Security News, revealed the use of both automated scripts and manual intervention to destroy IT, virtualization, and backup infrastructure.

Coordinated Effort Beyond LA Metro

The cyber campaign extended its reach beyond LA Metro, targeting other significant entities such as the South Florida Regional Transportation Authority, UNIMAC, and the consumer GPS service Vyncs. The attack also impacted sectors in Israel and Turkey, including media, education, and insurance, indicating a calculated and coordinated effort rather than random acts of hacking.

What distinguishes this attack is the systematic approach to eliminating recovery options. The attackers focused on eradicating backup systems, deleting database chains, and removing operating system files to thwart any restoration attempts. In one instance, an AI chatbot was leveraged to refine a custom script for destruction, adding a sophisticated layer to these state-linked cyber activities.

Advanced Methods of Data Destruction and Theft

The attackers employed a dual approach combining scripted automation and manual system manipulation. At LA Metro, they dismantled virtual machines using the agency’s own virtualization platform. At UNIMAC, they erased storage volumes and left behind the “Minab” signature. In a similar vein, at Vyncs, a custom Python script targeted 58 SQL Server databases, successfully eradicating all with no failures. Concurrently, SQL backup files and key Windows system folders were manually deleted to ensure total destruction.

In addition to the destruction, investigators found two custom data theft tools in use. One tool compressed and uploaded stolen files to the victim’s website, retrieving them via an attacker-controlled server. Another tool, FileFiend, scanned for files and transmitted them to a command-and-control server.

Implications and Recommendations for Organizations

The most conclusive link to Black Shadow came via a staging server previously used to target Israeli soldiers with a fake support site in August 2025. Organizations in critical sectors such as infrastructure, transportation, and education are urged to reassess their access controls, backup isolation, and incident response measures in the wake of these attacks.

The breadth and sophistication of this cyberattack underscore the necessity for heightened vigilance and robust cybersecurity measures. As the threat landscape evolves, the ability to respond swiftly and effectively to such coordinated attacks becomes imperative for organizations worldwide.

Cyber Security News Tags:Black Shadow, Cyberattack, Cybersecurity, data destruction, Gambit Security, Hacking, Iran, IT systems, LA Metro, Middle East

Post navigation

Previous Post: Critical Linux Kernel Flaw Endangers Systems with Root Access
Next Post: Evolving Beyond vCISO: The Rise of Security Growth Platforms

Related Posts

Anthropic Introduces AI-Driven Code Security Analysis Anthropic Introduces AI-Driven Code Security Analysis Cyber Security News
Hackers Mimic IT Teams to Exploit Microsoft Teams Request to Gain System Remote Access Hackers Mimic IT Teams to Exploit Microsoft Teams Request to Gain System Remote Access Cyber Security News
Stryker Faces Cyber Breach: Data Erased Globally Stryker Faces Cyber Breach: Data Erased Globally Cyber Security News
Hackers Exploit Npm Package to Target AI Developers Hackers Exploit Npm Package to Target AI Developers Cyber Security News
Salesforce Fixes Major Marketing Cloud Security Flaws Salesforce Fixes Major Marketing Cloud Security Flaws Cyber Security News
Criminal IP to Unveil AI Security Advances at Infosecurity Europe Criminal IP to Unveil AI Security Advances at Infosecurity Europe Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SCALR AI: A Free AI Platform for Security Teams
  • ServiceNow Fixes Critical Code Injection Vulnerabilities
  • Enhancing Security with Anthropic’s New Compliance API
  • Adware Conceals ValleyRAT Backdoor in China and India
  • Kaspersky Product Zero-Day Exploit Unveiled by Nightmare Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SCALR AI: A Free AI Platform for Security Teams
  • ServiceNow Fixes Critical Code Injection Vulnerabilities
  • Enhancing Security with Anthropic’s New Compliance API
  • Adware Conceals ValleyRAT Backdoor in China and India
  • Kaspersky Product Zero-Day Exploit Unveiled by Nightmare Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark