Iran-Linked Hackers Wipe IT Systems and Backups in Middle East Cyberattack

Gambit Security’s Threat Intelligence team has uncovered a fast-moving, destructive cyber campaign that targeted organizations across the United States, Israel, Saudi Arabia, and Turkey.

Public reporting of the activity began in late March and early April 2026 after a pro‑Iranian persona calling itself “Ababil of Minab” claimed responsibility for compromising the Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro), exfiltrating data, and wiping systems.

Gambit’s investigation shows the operation is far more extensive and more dangerous than the persona’s claims imply. Forensic links and infrastructure ties in Gambit’s analysis point to a campaign connected to previous Iran‑linked operations.

The technical artifacts and network infrastructure match activity that the Israel National Cyber Directorate (INCD) publicly attributed to Iran’s Ministry of Intelligence and Security (MOIS).

That suggests Ababil of Minab is not an independent hacktivist group but part of a larger, state‑aligned effort. Gambit also recovered bespoke exfiltration tooling and identified additional victims in Israel and Turkey that the attackers did not publicly disclose.

The attackers combined data theft with targeted destruction. Across different victims, Gambit observed exfiltration followed by destructive actions against IT systems, applications, virtualization platforms, storage volumes, and backups.

The destructive techniques included scripted deletions of virtual machines and storage, manual hands‑on‑keyboard removal of databases, and removal of backup copies.

These methods are modular and layered: some actions ran automatically, while others required human operators to execute targeted removals.

Each destructive technique presents unique recovery challenges. Deleting virtual machines and snapshots breaks platform-level recovery paths and can corrupt interdependent services.

Removing database instances or storage volumes can destroy application state and transactional histories that are hard to reconstruct. Wiping backups or their metadata is the most damaging step because it removes the last line of defense against full recovery.

When attackers operate across these layers, restoration requires multiple parallel processes rebuilding virtual environments, restoring databases from surviving copies or logs, and validating application integrity making recovery slow and costly.

Gambit formed its team to focus on exactly this problem: bridging threat intelligence with operational resilience.

Their full report provides detailed attribution evidence, the custom exfiltration tooling they recovered, a list of additional victims in Israel, Saudi Arabia, and Turkey, and a step‑by‑step breakdown of the destructive playbook.

For defenders, the takeaway is urgent: shift some security investment from pure prevention to verifiable recoverability. The question security teams must now ask is not only “can we keep them out?” but also “when they get in, can we bring it back?”

If you manage backups, virtualization, or incident response, prioritize tabletop exercises that simulate simultaneous exfiltration and destruction.

Those exercises expose recovery gaps that conventional intrusion prevention testing rarely finds and help build the muscle memory needed to survive this new class of attacks.

Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories