BoletimSec•September 9, 2026•🇵🇹Translated from Portuguese

US Offers $10 Million Reward for Iranian IRGC Cyber Commander Amir Yaryab

The United States is offering a reward of up to $10 million for information that leads to the identification or location of Amir Yaryab, leader of the cyber command of Iran's Islamic Revolutionary Guard Corps (IRGC).

According to US authorities, Yaryab heads the Cyber Operations Command of the IRGC Cyber-Electronic Command and supervises units involved in operations against critical infrastructure. Among the groups under his direction are Shahid Hemmat and Shahid Shushtari, associated with campaigns targeting defense, energy, telecommunications, finance, transportation, hotels, and airlines sectors in the United States, Europe, and the Middle East.

Yaryab is also linked to structures connected to the CyberAv3ngers group, known for attacks against industrial systems and operational technology equipment. The objectives of these operations include espionage, disruption, and manipulation of critical systems.

Previous Campaigns and Technical Details

Earlier campaigns attributed to IRGC-linked actors compromised internet-exposed Unitronics programmable logic controllers. Between November 2023 and January 2024, at least 75 devices were affected, including 34 used in the US water and wastewater sector. The attackers primarily exploited equipment with default passwords or lacking adequate protection. In some cases, they altered control logic, remote access credentials, and operator interface screens.

The reward is part of the Rewards for Justice program and covers information on individuals who, under the direction of foreign governments, participate in malicious cyber activities against US critical infrastructure.

Related articles

BoletimSec•State-Sponsored & APT

North Korean WaterPlum Group Infects 30,000 Computers Across 100 Countries via Fake Coding Tests

The North Korean-linked group WaterPlum, also known as Contagious Interview, has infected at least 30,000 computers in more than 100 countries between December 2025 and July 2026. According to the Internet Crime Complaint Center (IC3), the operation moved at least $10.7 million in cryptocurrency to North Korea and compromised more than 7,000 wallets. Attackers pose as recruiters on social media and freelance platforms, luring software developers with nonexistent job offers that require downloading malicious files disguised as coding tests. The malware arsenal includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, with the latter hiding inside blockchain-themed projects and abusing Visual Studio Code configurations. Developers are specifically targeted because they often store production keys, wallets, and credentials on the same machines used for testing third-party code. Japanese authorities have dismantled laptop farms connected to the scheme that helped maintain the attackers' operational cover.

BoletimSec•State-Sponsored & APT

APT28 Expands Espionage with New HOOKEDGE Backdoor Targeting European Organizations

The Russian-linked APT28 group, also known as BlueDelta, has deployed a new lightweight backdoor called HOOKEDGE as part of a cyber-espionage campaign against strategic European entities. The attacks, assessed with moderate confidence, targeted government, diplomatic, and defense manufacturing organizations in Romania, Spain, and Turkey between September 2025 and April 2026. Infection begins with spear-phishing emails delivering Microsoft Word documents containing malicious macros that mimic official Spanish government materials. Upon execution, the macros drop files, establish persistence via scheduled tasks, and deploy the HOOKEDGE backdoor written in batch scripts. The malware uses hidden Microsoft Edge instances and the legitimate webhook.site service to blend command-and-control traffic with normal web activity. In high-value victims, operators installed a second HOOKEDGE instance with five-minute check-ins for faster control and data collection. The backdoor shows strong code similarities to the older HEADLACE implant previously attributed to the same group.

BoletimSec•State-Sponsored & APT

Iran-Linked Cyber Attack Leaves Small UK Power Plant Offline for Four Days

A cyber attack attributed to hackers with suspected ties to Iran took a small-scale UK power generation facility offline for approximately four days in July 2026. The incident affected a roughly 15 MW generator used to support peak demand periods, yet caused no customer outages or disruption to the national electricity grid. British authorities have not issued an official attribution, and investigators have not publicly identified the malware, vulnerability, or initial access vector used in the operation. Recovery required four days of extensive validation across controllers, configurations, security systems, and remote access points to ensure no residual risks remained. The case highlights the operational challenges of restoring industrial control environments after suspected nation-state activity. In response, UK authorities have strengthened guidance for the energy sector and are considering additional protective measures for critical infrastructure suppliers.

BoletimSec•State-Sponsored & APT

Iran-Linked Tortoiseshell Group Deploys Malicious wtsapi32.dll Backdoor for Persistent Windows Access

Researchers have uncovered new tools deployed by the Tortoiseshell group, an Iranian-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore. The campaign features a Windows backdoor disguised as the legitimate wtsapi32.dll library that silently establishes reverse SSH tunnels over port 443 to maintain access to compromised networks. Active since at least 2018, the group has targeted defense, aerospace, technology, IT services, and military organizations primarily in the Middle East and the United States. The malware preserves expected Windows API functions while enabling command execution, file exfiltration, in-memory DLL loading, directory listing, and system reconnaissance. Associated infrastructure spans the United Arab Emirates, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia, and Japan.