Iran’s railways and transport ministry were hit by a cyberattack that took down their websites and disrupted train service throughout the country last month. The attackers deployed a previously unseen file wiper called Meteor on the targets’ systems. Check Point Research identified a threat actor dubbed Indra, who previously deployed wiper malware on the networks of multiple Syrian organizations. Indra identify themselves as a group opposing the Iranian regime. However, the group chose not to take responsibility for last month’s attacks against the Iranian Railways and the Ministry of Roads and Urban Development.”]

