Actor Profile
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring sensitive technical and military information. Their operations demonstrate advanced tradecraft including DLL hijacking techniques and custom remote access tooling.
TTPs (Tactics, Techniques, Procedures)
The group's primary TTPs include AppDomainManager hijacking for persistence and defense evasion (T1574.002 - DLL Side-Loading), deployment of custom RAT variants for remote access (T1219 - Remote Access Software), and likely initial access through spearphishing or supply chain compromise targeting technology and defense organizations. The use of AppDomainManager hijacking indicates sophisticated understanding of .NET execution flows for stealthy persistence.
Targets & Patterns
Screening Serpens targets the technology and defense sectors, likely seeking intellectual property, defense-related technical data, and strategic intelligence. These sectors align with Iranian strategic priorities including military modernization, technology acquisition, and monitoring of adversary capabilities. The dual-sector focus suggests interest in both commercial technology transfer and defense intelligence collection.
Historical Context
This 2026 campaign represents reported activity by Screening Serpens as documented by Unit 42. The use of AppDomainManager hijacking and new RAT variants indicates evolution in the group's toolset and operational techniques. No prior campaign data is available in the provided information to establish longitudinal patterns.
Defensive Recommendations
- Monitor for AppDomainManager hijacking by detecting unusual AppDomainManager.dll loads or modifications to application configuration files that specify custom AppDomainManager classes
- Implement application whitelisting and code signing verification to prevent execution of unauthorized DLLs in .NET application directories
- Detect T1219 Remote Access Software by monitoring for unusual outbound network connections from workstations, particularly to Iranian infrastructure or newly registered domains
- Enable enhanced logging for .NET assembly loads (ETW Provider Microsoft-Windows-DotNETRuntime) to identify suspicious AppDomain manipulation
- Conduct threat hunting for RAT indicators including unusual process injection, credential access attempts, and lateral movement from initially compromised technology/defense sector endpoints
---
# Geopolitical Context
Geopolitical Context
The reported activity attributed to Screening Serpens is consistent with Iran's sustained cyber espionage priorities targeting Western and allied defense industrial bases and technology sectors. Iranian state-aligned APT groups have historically pursued intelligence collection on military capabilities, dual-use technologies, and strategic industries amid ongoing regional tensions and sanctions pressure. The use of advanced techniques such as AppDomainManager hijacking and custom RAT variants indicates continued investment in operational tradecraft, likely reflecting Tehran's reliance on cyber operations as an asymmetric tool to offset conventional military disadvantages and gather strategic intelligence on adversaries' defense postures and technological developments.
State Actor Alignment
Screening Serpens is assessed to be an Iranian state-aligned advanced persistent threat group. Iran's cyber program operates under the Islamic Revolutionary Guard Corps (IRGC) and Ministry of Intelligence and Security (MOIS), with multiple APT groups conducting espionage and disruptive operations in support of national security objectives. Iranian cyber actors remain subject to U.S., EU, and allied sanctions frameworks targeting malicious cyber activity. The targeting of defense and technology sectors aligns with Iran's documented intelligence requirements regarding military modernization, sanctions evasion, and monitoring of adversary capabilities, particularly amid heightened tensions with Israel, Gulf states, and Western powers.
Business Impacty pro region
The targeting of defense and technology sectors carries significant implications for transatlantic security and allied defense cooperation. European defense contractors, technology firms with dual-use applications, and NATO-aligned industrial partners represent high-value targets for Iranian intelligence collection. Compromises in these sectors may enable Tehran to acquire sensitive information on weapons systems, supply chain vulnerabilities, and emerging technologies such as artificial intelligence and autonomous systems. The activity may prompt increased threat intelligence sharing among Five Eyes partners and NATO allies, as well as enhanced scrutiny of supply chain security in defense procurement. Middle Eastern states with advanced technology sectors, particularly Israel and Gulf Cooperation Council members, likely face elevated risk from parallel or related campaigns.
Forecast
If Screening Serpens maintains operational tempo through 2026, additional intrusions targeting defense contractors and technology firms in North America, Europe, and allied states are likely. Should geopolitical tensions escalate—particularly regarding Iran's nuclear program, regional proxy conflicts, or sanctions enforcement—Iranian APT activity may intensify or shift toward more disruptive operations. Defenders should anticipate continued evolution of Iranian tradecraft, including adoption of living-off-the-land techniques and custom malware to evade detection. If attribution becomes more widely publicized, targeted governments may impose additional cyber-related sanctions or pursue coordinated defensive measures, potentially prompting Iranian actors to adjust infrastructure and operational security practices.
