Iran-Linked Cyber Campaign Targeted Israel, UAE, Iraq
Translated & summarized from Maariv by baba
Palo Alto Networks researchers identified a cyber campaign linked to Iran targeting Israel, Iraq, and the UAE. The attackers used fake recruitment portals and impersonated Dubai Airports, and in Israel, they used "unpublished war documents" to steal login credentials. The campaign also notably incorporated elements from the "Peaky Blinders" TV series. The full extent of the breaches and successful data theft remains unconfirmed.
The story in 6 lines · by baba
- A cyber campaign linked to Iran targeted Israel, Iraq, and the UAE, according to Palo Alto Networks.
- Attackers used fake recruitment portals and impersonated Dubai Airports to compromise systems.
- In Israel, "unpublished war documents" were used as bait to steal login credentials.
- The "Peaky Blinders" TV series was unusually incorporated into the attackers' infrastructure.
- GitHub removed malicious infrastructure used in the campaign.
- The success of the attacks and the extent of data theft are currently unconfirmed.
Cybersecurity researchers at Palo Alto Networks have uncovered a sophisticated cyber campaign attributed to actors with ties to Iran, targeting entities in Israel, Iraq, and the United Arab Emirates. The attackers employed tactics such as impersonating Dubai Airports and creating fake recruitment portals with programming tests to lure victims. In Israel, a campaign in May and June 2026 used bait documents titled "unpublished war documents" hosted on a fake Google Drive page to steal login credentials. The attackers also leveraged the GitHub development platform to transfer instructions and download additional malware, disguising malicious communications within legitimate activity. GitHub has since removed the identified malicious infrastructure.
The campaign's scope included attempts to compromise critical infrastructure, aviation, and communication sectors. Researchers were able to link the various attacks through shared infrastructure and the attackers' unusual use of the popular TV series "Peaky Blinders." They incorporated the show's name, characters, and even its theme song into their attack infrastructure, with the song's metadata pointing to an Iranian music site. This, along with other findings, supported the researchers' assessment of Iranian involvement. Palo Alto Networks has not confirmed the success of the attacks against the targets in Iraq or whether any credentials were successfully stolen in Israel, nor is there information about a breach at Dubai Airports.
Mentioned
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 2
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.