According to Palo Alto Networks, hackers backed by the Iranian government are using spear-phishing attacks and remote access trojans (RATs) to conduct espionage against "high-value industries" in the United States and the Middle East, a move seen as part of Tehran's response to the war with the U.S. and Israel.

The company's Unit 42 researchers recently discovered six new RATs used for espionage by an Iran-linked group called Screening Serpens. Researchers said the group's "activity has increased" since the war began, with malware metadata indicating its targets span "the U.S., Israel, and [the UAE] as well as two other Middle Eastern entities."

Screening Serpens—referred to by other researchers as UNC1549, Smoke Sandstorm, or Nimbus Manticore—has, according to Palo Alto Networks, "consistently kept its sights on high-value industries," particularly in aerospace, defense, and telecommunications.

Researchers wrote: "A notable feature of recent activity is the deep personalization of attacker lures. By leveraging tailored social engineering tactics, including fake job postings and forged video conference invitations, attackers entice victims to initiate the infection chain, putting their organizations at risk of further exploitation."

This new report is the latest evidence of Iran's attempts to maximize its use of cyberspace to counter the U.S. and its allies as the war enters its fourth month. Previously, hacker groups linked to Tehran were found attacking Middle Eastern city governments and U.S. infrastructure operators.

Malware combined with meticulous planning

The six new RATs belong to two malware families. The first family, MiniUpdate, appeared in two campaigns targeting U.S. and Israeli organizations in late March, then seemed to target organizations in the UAE and possibly another Middle Eastern country in a campaign in mid-April. According to Palo Alto Networks, the U.S. activity involved customized spear-phishing lures where hackers posed as a major airline; in the Middle Eastern attacks, hackers first posed as a healthcare organization and then as a financial services company.

In February and March, researchers detected RAT attacks involving the second malware family, MiniJunk V2. The February attack targeted an IT professional working in the Middle East and involved months of planning and research, with malware development beginning in late 2025 when hackers were studying the target's movements in search of a new job.

Palo Alto Networks stated: "The threat actor conducted meticulous reconnaissance, leveraging the target's active job-seeking traces to craft tailored lures. To establish legitimacy and entice the target to execute its payload, the attacker shared a forged recruitment URL from a well-known legitimate job site."

As of April, the report says, Screening Serpens "continues to orchestrate persistent, adaptive global cyber activities." "Organizations may face further attempts in the near term and should strengthen their defensive posture to prepare for potential intrusion attempts."