Iran-Linked APT compromises maritime firms to map AIS coverage blind spots

Year

2025

Month

November

Reference number

20251120

Impact area

Shore

Incident location

Israel

Incident country

Israel

Victim country

Israel

Victim identity

Israeli maritime intelligence companies; AIS analytics platforms

Victim Type

Maritime intelligence companies, AIS analytics provider, defense-adjacent Israeli private sector organizations

Method

Credential theft

Attacker country

Iran

Summary:

An Iran-linked threat group compromised multiple maritime-sector organization and accessed specialized tools used to visualize AIS signal coverage globally. The actors used these tools to identify geographic AIS blind spots where vessel tracking is limited or absent. This intelligene enables covert vessel repositioning, sanctions evasion, smuggling, military deception and potentation support for physical operations at sea. The intrustion demontrates a shift from simple AIS manipulation to pre-operational cyber-espionage targeting AIS infrastructure itself.

Reference URL

https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
https://www.asadria.com/emazon-blames-iran-for-combining-cyber-espionage-with-physical-attacks/
https://www.csoonline.com/article/4093375/iranian-apt-hacks-helped-direct-missile-strikes-in-israel-and-the-red-sea.html