The user, operating under the name Sadpainy, released code intended to replicate Stuxnet, the malware that reportedly destroyed a fifth of Iran's uranium enrichment centrifuges.
The shift aligns with CISA's June Binding Operational Directive (BOD), which guides federal civilian agencies in prioritizing security updates based on real-world risk rather than solely on static CVSS scores.
These groups are employing a range of sophisticated techniques, from exploiting valid credentials to deploying custom backdoors and ransomware, indicating a significant rise in targeted cyber threats against Russian organizations.
The BragJack attack, detailed by researcher Gal Weizman of Forever Security, targets Google Chrome with Gemini, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome.
The malware, attributed to Iran's Ministry of Intelligence and Security (MOIS), has been active since at least 2025, targeting individuals critical of the Iranian government.