Predatory_Sparrow__2021__Indra_Hackers_Behind_Recent_Attacks_on_Iran_-_Check_Point_Research.pdf
ID: 6e24a53f-1724-46eb-8bb1-e4c122c60142
STIX ID: report--6e24a53f-1724-46eb-8bb1-e4c122c60142
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2021-08-16
Last Modified Date: 2021-08-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Threat actor Indra conducted coordinated cyber attacks against Iran's railways and transportation infrastructure using sophisticated multi-stage wiper malware variants (Meteor, Stardust, Comet), including a complex executable and batch/VBS-based delivery chains, anti-forensic measures, and boot/log destruction. The study links these Iranian operations to prior Syria-targeted campaigns, provides IoCs and YARA signatures, and highlights Indra’s public activities and claims across social platforms.
