Archive for FBI

The CISA and FBI advise organizations to drop PR spin during major IT, OT outages 

Posted in Commentary with tags , on September 3, 2026 by itnerd

The CISA and the FBI, alongside cybersecurity agencies from Australia, Canada, New Zealand and the UK, have released new guidance for communicating during major IT and OT outages, warning that poor communication can compound the operational damage caused by an incident.

The agencies specifically advise organizations to avoid PR and marketing language, clearly state what is known and unknown, and provide customers with technical and actionable information rather than vague descriptions such as “service degradation.”

The guidance recommends that organizations establish outage communication plans before an incident, including predefined thresholds for when notifications are required, designated spokespeople, backup communication channels and procedures for reaching customers, regulators and critical infrastructure operators.

During an outage, providers should explain which systems are affected, the scope and operational impact, and the known cause without speculating when an investigation is still underway. The agencies also call for continuous, time-stamped updates throughout an outage, including recovery milestones and actions being taken.

Joshua Marpet, Senior Product Security Consultant, Finite State:

“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great. Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability. Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have an perfect example of Marpet’s law “Unless it’s mandated, or someone is paying for it, ain’t gonna happen”

“The EU CRA is a great example of mandating that type of communication. 24 hours, 72 hours, and 14 days, after an incident, there are specific types of communications with defined pieces of data you MUST give to the public and stakeholders. This is what we need, not best wishes and prayers.”

Denis Calderone, CTO, Suzu Labs:

“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency. All of that has been in every incident response framework going back to NIST 800-61. Where this guidance actually adds value is in the operational specifics and the timing. It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis. That means establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them. When I run tabletop exercises for clients, one of the first things I do is take their communications down. Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for.

“The timing also matters. This drops alongside CISA’s CI Fortify initiative, which tells critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis. If you’re a water utility or a power plant making a real-time decision about whether to isolate, you need your service providers telling you exactly what is happening and what is not happening. The guidance specifically calls for articulating “what it is and what it is not” to prevent misattribution. After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of “was this a nation-state attack?” speculation while downstream operators are making blind isolation decisions.

“What gives this more weight than a typical government advisory is who helped write it. Microsoft, Sophos, Cloudflare, and American Water all contributed. Cloudflare’s November 2025 outage is explicitly cited as an informing event, and for good reason. Their status page went down during the incident, their own response team initially misidentified the root cause partly because of the communication breakdown, and the whole thing spiraled. The organizations that have been through it are helping write the playbook, and that gives the operational details real credibility.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I think everything in this plan is great. There’s just one area I wish they would address more directly. When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls.

“During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?

“What often happens is that the decision gets escalated again and again and again until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call. Meanwhile, valuable time is being lost.

“Incident response plans need to go deeper than motherhood and apple pie statements about communicating with customers, coordinating between organizations, and keeping everyone informed. That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident.

“Just as importantly, there needs to be political cover for the people who make those decisions.

“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was absolutely necessary. The person making that decision in the middle of an active breach doesn’t have that luxury.”

Notifications should never be like Apple release notes of “bug fixes and performance improvements”. They should have clear communication in them 100% of the time. Organizations need to work on that now.

Chinese hacking platform takedown exposes an ORB network hiding in your routers 

Posted in Commentary with tags , on August 27, 2026 by itnerd

The DOJ and FBI just disrupted QTFY, a Chinese state-linked hacking platform built around QScan, which scanned the internet for vulnerable IoT and SOHO devices, and QTRouter, which enrolled those devices into an obfuscation mesh to hide attacker traffic. Authorities seized the domains hard-coded into the malware, making the tooling inoperable across every operation that relied on it, not just one campaign. The FBI also flagged business ties between the company behind QTFY and groups like Salt Typhoon and i-Soon.

Josh Picolet, VP of Detection & Analysis, Team Cymru had this to say:

“QTFY is a useful case study in how state-linked contracting networks actually operate. The detail worth noting is what QScan was built to do. It scanned the internet, likely in a very targeted manner, for vulnerable IoT/SOHO devices and enrolled them into QTRouter, the layer that hid the actual operations behind a mesh of compromised hardware. That is the operating model of an ORB network, an operational relay box mesh assembled from hijacked edge devices, and it is exactly the type infrastructure ecosystem we have been tracking at Team Cymru for years. QTFY is one network in a much larger pattern. Turning routers, IoT gear, and SOHO devices into an obfuscation layer for attacker traffic is not a one-off tactic bolted onto a single contractor. It is how China’s freelance hacking and contracting market has learned to work, and the business ties noted here to Salt Typhoon and i-Soon are the visible edge of a quartermaster model that resells capability and access across many customers.

That model is also why the takedown landed the way it did. The domains were hard-coded into the malware for communication and authentication, so seizing that infrastructure made the tooling inoperable across every operation depending on it, not just one intrusion. Detection built around a single campaign’s indicators would never have surfaced a platform built to be shared across operators. What exposes infrastructure like this is the ability to detect the shared obfuscation layer underneath the operations, recognizing the mesh as a repeatable tradecraft pattern rather than a scatter of unrelated victims.

Defenders should not expect this one to fade. The quartermaster model and the compromise of edge devices for obfuscation will be fought for years to come. We track a large number of these ORB mesh networks, and the modus operandi across them is remarkably consistent. That is why we tag and track every model of router, IoT, and SOHO device we can observe, so these networks can be detected early and customers get a real risk level on the IPs involved. Organizations in defense, telecom, and critical infrastructure should be asking whether their own detection reaches that layer, well past the perimeter.”

Disruptions like this are good. But what will really solve the issue is going after the people behind these schemes and bringing them to justice. That way the profitability gets taken out of activities like these.

The FBI created its own crypto token to catch a $7.5 billion pump-and-dump fraud ring

Posted in Commentary with tags on August 26, 2026 by itnerd

A UK judge rejected Manpreet Kohli’s fight against extradition to the US on wire fraud and market manipulation charges tied to Saitama, an Ethereum-based token he led that peaked at a $7.5 billion market value, with prosecutors alleging he and more than a dozen co-conspirators publicly claimed to be holding and buying the token while privately selling their own holdings for millions in profit. The case marks the first known instance of the FBI creating its own digital token specifically to investigate this kind of fraud, and Kohli’s case now goes to UK ministers to decide on extradition, with Kohli free on £200,000 bail and able to appeal.

More details here: Cryptocurrency chief facing extradition from UK to US on fraud charges – Yahoo News Canada

Jason Brown, Director of Counter Fraud Operations, iCOUNTER:

“A token does not reach a $7.5 billion valuation in isolation. The activity moved through market makers, exchanges, wallets, and counterparties. That is the third-party problem in one sentence, and it is why detection has to start outside your perimeter.

What’s notable in this case is how the FBI worked the whole ecosystem, not just the issuer. Prosecutors say Kohli and his co-conspirators publicly claimed to be holding and buying Saitama tokens while privately selling their own holdings for millions in profit. Kohli alone is alleged to have made around $20 million. That’s a classic pump-and-dump dressed up in crypto terminology. But the same investigation went after the market makers hired to manufacture the volume, and to reach them the FBI stood up its own token, NexFundAI, and watched firms like ZM Quant and CLS Global manipulate it in real time. Trading was disabled before retail investors were exposed. The issuer and the vendors were two halves of one campaign, and neither half was visible from inside a single platform.

That’s the lesson for anyone running fraud detection today, in crypto or otherwise. The Saitama token itself was never the crime scene. The crime happened in the gap between what was said publicly and what was done privately across wallets and counterparties, and you only see that gap if you’re watching the full network, not just the asset. A $7.5 billion valuation built on that kind of coordinated deception should be a wake-up call for anyone who thinks perimeter-level monitoring of a single platform or exchange is sufficient. It isn’t. The fraud is distributed by design, and the detection has to be too.”

Fact: Every one of these people need to be extradited to face the legal system (such as it is in the US). That is the only way that bad guys will stop doing bad things.

FBI investigates newly disclosed breach of U.S. water technology supplier

Posted in Commentary with tags on August 26, 2026 by itnerd

The FBI is investigating a previously unreported cyberattack on Micro-Comm, a Kansas company that makes programmable logic controllers (PLCs) used by wastewater facilities. Micro-Comm discovered the breach on July 31, and the Barracuda ransomware group subsequently published what it claimed were nearly 850,000 stolen files totaling roughly 644 GB of data.

What makes this incident different from the recent attacks on individual water utilities is that the hackers compromised a supplier of the technology used to operate water infrastructure. A list of the stolen files reportedly references specific government customers, including local governments and a U.S. military facility, as well as employee information and product diagrams. Roughly 200 Micro-Comm SCADAview CSX systems currently in use across the U.S. are accessible from the internet.

Micro-Comm said passwords, customer credentials and information enabling remote access to its devices were not exposed, and there is no evidence that the breach resulted in the operational compromise of a water system. The FBI also told the company that the attack appeared opportunistic and separate from the recent campaign targeting water utilities in at least seven states.

Donald McFarlane, Advisory Board Member, Xcape, Inc.

   “The Micro-Comm incident may well have been an opportunistic ransomware/data-theft attack which is unconnected to the other recent attacks on OT.  Nevertheless, that does not make the information stolen from it unimportant.

   “An attack on one utility gives you one victim.  An attack on a control-system supplier can potentially give you a map to hundreds of victims.  Customer identities, engineering information, product diagrams and other technical data can significantly reduce the reconnaissance burden for somebody who wants to attack those systems later.

   “Moreover, AI changes the economics of exploiting a large data dump.  An adversary can use AI to help sift through the information, correlate customers with products and configurations, analyze engineering documentation, and if source code or other implementation details are available, look for product vulnerabilities worth exploiting.  This matters all the more when roughly two hundred Micro-Comm systems are already reachable from the internet.

   “You don’t need to steal the remote-access password for stolen engineering information to have intelligence value.

   “Micro-Comm isn’t Siemens, Schneider or Rockwell.  Despite manufacturing their own line of PLCs, it is a much smaller specialist manufacturer whose scale is closer to that of many regional control-system integrators than to the major global automation vendors.

   “And that raises a broader concern: if we’re anticipating targeted adversarial activity rather than simply reacting to opportunistic ransomware, the integrator community deserves particular attention.  The system integrators are often small regional engineering companies, but they may hold PLC programs, network diagrams, customer configurations and remote-access pathways for dozens of critical-infrastructure operators. From an adversary’s perspective, that’s an extraordinarily valuable concentration of information.

   “The company maintaining the keys and blueprints to a few hundred water systems may have fifty employees. That doesn’t make it a small target.”

Denis Calderone, CTO, Suzu Labs:

   “The ICS threat landscape is getting much more sophisticated. In 2023, CyberAv3ngers were simply changing default passwords on Unitronics PLCs and putting political messages on HMI screens. But by July of this year, CISA confirmed that actors were exfiltrating PLC project files using the vendors’ own engineering software and modifying Add-On Instructions to disable safety shutdowns while leaving the operator displays looking normal. Last week, five federal agencies warned that attackers are now using AI to generate working exploitation scripts against Siemens S7 controllers, calling it an evolution that ‘dramatically reduces the technical expertise and time required.’ That’s the trajectory, and the Micro-Comm breach feeds into that narrative.

   “What makes the Micro-Comm breach so dangerous is the stolen proprietary data. The five-agency advisory said threat actors are collecting public information about PLC vulnerabilities and using AI to generate scripts that act on it. Now, imagine what becomes possible with a non-public disclosure? There are product diagrams, system architecture documents, customer-specific configurations, details about how SCADAview CSX communicates with the controllers it monitors. You hand that documentation to an unguardrailed AI model and the output is not generic Modbus reads on port 502, it’s targeted tooling built against a specific vendor’s implementation, informed by the manufacturer’s own engineering materials. That’s the difference between FrostyGoop’s 300 lines of Go sending blind register writes and something purpose-built to manipulate the logic in a specific way that an operator won’t notice.

   “The FBI says this was opportunistic ransomware, and the attackers probably didn’t know what they had. Barracuda is selling it for $30,000. But there are roughly 200 SCADAview CSX systems sitting on the public internet right now according to Censys, and the buyers of this data may have very different intent than the people who stole it. The joint advisory (AA26-231A) pointed out that the Siemens attack had pre-positioning as one of its goals, so utilities running Micro-Comm equipment should be getting those systems off the internet today, rotating every credential, and asking their integrator to verify that PLC project files match a known-good baseline. If you rely on this vendor’s products, you need to stay diligent. The window between when this data hit the market and when someone with real capability decides to use it is the only time you have to close the gap.”

Critical infrastructure needs to be protected. Or hacks like this will be commonplace. That is as commonplace as every other hack that currently exists. Which is a really sad state of affairs.

The FBI Warns of Hackers Using AI to Break into Water Systems

Posted in Commentary with tags on August 20, 2026 by itnerd

The FBI ,NSA CISA and other U.S. federal agencies are warning owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs. Threat actors are targeting U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected.

The most targeted sectors include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.

More details can be found here: https://www.ic3.gov/CSA/2026/260819.pdf

Dan Moore, Sr. Director CIAM Strategy at FusionAuth, provided the following comments:

“People are already using AI to one-shot drivers for obsolete printers, so sophisticated actors were bound to go after long-lived, seldom-updated, high-value systems like these PLCs.

Using AI gave attackers faster discovery and exploitation of the attack surface. The suggested defenses are what we’ve heard over and over again: apply patches, don’t put systems on the internet, use strong access controls, monitor important systems, and don’t leave authentication in the default state.

Hackers don’t need AI to discover new vulnerabilities. All they need to do is exploit weaknesses that we know we should have patched long ago.”

Critical infrastructure should get about patching all the things. Because the nation depends on their actions.

Gunra ransomware group bypassing MFA and exfiltrating enterprise data via Fortinet flaws

Posted in Commentary with tags , , on August 11, 2026 by itnerd

The FBI, CISA, and South Korea’s National Police Agency issued a joint advisory Monday on Gunra ransomware, also known as Golden Community. The RaaS operation exploits two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, for initial access, then runs double extortion against healthcare, financial services, and government targets worldwide.

Roman Sannikov, Global Research Coordinator, iCOUNTER

“Gunra’s exfiltration playbook is what should worry Microsoft 365 shops specifically. The advisory documents a custom executable pulling data straight out of OneDrive and SharePoint, then in at least one case moving the archived data out to Mega in volumes running into the tens of terabytes. Getting into position to do that took real infrastructure: the actors moved laterally using Impacket tools over SMB and hijacked active sessions by stealing VPN cookies, all before touching a single file. Moving that much data without tripping alerts takes real operational patience, and it fits a pattern: CISA notes the actors deliberately operate between 10pm and 6am to stay under the radar of anyone watching logs during business hours. Once they do start encrypting, it’s fast, ChaCha20 paired with RSA-4096 across a multi-threaded engine hitting multiple files at once. If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

These advisories are not made lightly. So organizations need to pay attention. Especially Microsoft 365 shops to avoid being pwned by these threat actors.

UPDATE: Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this comment: 

“Gunra made multi-factor authentication (MFA) lie for them. In the South Korean case, the group modified virtual desktop infrastructure (VDI) authentication files to accept a hardcoded attacker-chosen one-time password, and every subsequent login looked legitimate to monitoring tools. Most organizations treat MFA as the last line of defense. Gunra treated it as the first thing to subvert.

“The sector targeting is economic. Healthcare, financial services, and government can’t tolerate downtime or survive a data leak. Encrypting their systems while threatening to publish stolen records hits both pressure points at once.

“CVE-2024-55591 and CVE-2025-24472, the two Fortinet authentication bypasses that got them initial access, are eighteen months old and have been exploited by multiple ransomware groups. Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.

“The advisory also flags a recoverable flaw in Gunra’s Linux encryptor. The variant seeds its ChaCha20 keys with time() instead of a secure random number generator, so defenders who preserve file timestamps can reconstruct keys without paying. Any organization hit by the Linux variant should get forensics involved before wiring cryptocurrency.

“Gunra created a “forticloud-sync” account with super user privileges and a hardcoded password on compromised Fortinet firewalls. That account survives a firmware update, and so do modified VDI authentication files. An organization that patches and stops there is giving Gunra a head start on round two.”

John Strand, Owner, Black Hills Information Security, Inc.:

“The goal of targeting critical infrastructure is really twofold. With nation-state attacks, the objective can be straightforward. You want to create pain for your adversary. But with ransomware groups, I think there are two things we need to understand.

“First, critical infrastructure has become a dinner bell. Ransomware groups have seen how exposed and neglected some of this infrastructure is in countries like the United States, and now they’re swarming toward it because they recognize the opportunity.

“The second factor is pain. There’s been a major push in the security industry for organizations to refuse ransomware payments. But that position becomes much more complicated when an attack against critical infrastructure potentially impacts hundreds of thousands or even millions of people. It’s one thing to say you won’t pay the bad guys when the impact is contained to your organization. It’s another thing entirely when water, power, healthcare, or essential municipal services are disrupted. At that point, refusing to pay may sound principled, but elected officials also have to answer to the people whose lives are being disrupted. That creates enormous pressure to restore those services as quickly as possible.”

FBI, Google And Black Lotus Labs Take Down Chinese Based Phishing As A Service Operation

Posted in Commentary with tags , , on June 15, 2026 by itnerd

It has been reported that in a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.

You can find the full story here: https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls/

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:

“Outsider Enterprise was dismantled, but no one was arrested, and only a hundred thousand dollars was recovered out of the billions it stole. What’s notable here is that there was no involvement with Chinese authorities. Until we have stronger international cooperation and enforcement, nothing is stopping these scammers from rebuilding and committing more crimes. This is especially true for adversarial countries like China and Russia, from which we cannot extradite criminals. Scammers and other cybercriminals can operate from those countries with impunity, so long as they don’t attack domestic targets.”

While this is positive, there needs to be much more of this sort of thing. This has to be unprofitable for threat actors, which will make them stop what they’re doing.

FBI Warns Of Device Code Phishing Attacks

Posted in Commentary with tags on May 22, 2026 by itnerd

The FBI has put out a warning about Kali365 and the spike in device code phishing attacks earlier this week:

Through the Kali365 platform subscription, cyber threat actors can capture “OAuth” tokens and gain persistent access to targeted individuals/entities’ Microsoft 365 environments. Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.

But the deeper story is why this class of attack is so hard to catch. There’s no malicious link, no spoofed login page — just a legitimate OAuth flow handing attackers a valid token, bypassing everything traditional security is trained to flag.

Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment:

“The FBI’s warning is well-placed, and the recommended mitigations — conditional access policies, blocking device code flows — are the right first response. But they address the front door.

The harder question is what happens once an attacker is already inside a legitimate session. When a token is stolen, the attacker isn’t a stranger to the system anymore. They’re operating with valid credentials through authorized pathways. Traditional controls see a clean session. They don’t see intent.

That gap gets wider as AI enters the picture. Copilots and agents connected to M365 mean a compromised session isn’t just access to stored data — it’s a potential entry point into ongoing AI workflows, retrieval pipelines, and generated outputs that can surface sensitive information in ways that are much harder to detect.

The industry conversation tends to stop at authentication. It needs to extend to the data layer — what’s actually moving through these systems, what it contains, who it’s about, and whether that movement aligns with policy intent. Because by the time data is in motion, the authentication question has already been answered. Correctly or not.”

As mentioned, this technique is particularly dangerous because it exploits legitimate authentication workflows, making detection more difficult. Thus the mitigations that are recommended are vital to keeping your organization safe.

If Your Router Was Reset To Factory Defaults, You Need To Replace It NOW

Posted in Commentary with tags , , on May 12, 2026 by itnerd

Fun fact. Or maybe it’s not so fun. The Russians have been exploiting security vulnerabilities for years in home ad small office routers. In the process the Russians can use these routers to execute attacks at will. Thus the The FBI and NSA took the really unusual step of getting a court order in order to find and remotely reset these routers to kick the Russians out of these routers. Though there’s a catch to that which I will get to in a moment. From CNET:

Federal agencies, including the FBI and NSA, disclosed on April 7 that a unit of Russia’s military intelligence directorate, the GRU group known as APT28 or Fancy Bear, has been systematically compromising home and small office routers since at least 2024, using the access to intercept credentials, authentication tokens and sensitive communications. The agency took the unusual step of remotely resetting thousands of affected US devices under a court order, but officials are warning that without action from individual router owners, the problem is far from solved.

Here’s the catch. The routers in question aren’t getting security updates as well. So it is entirely likely that the Russians can simply come back and set up shop again if you leave the router in operation. Thus if your router gets reset remotely, it needs to be replaced. Immediately. As in now. Today.

If you’re wondering which routers are targeted, CNET can help you with that:

The UK’s National Cyber Security Centre includes a number of TP-Link routers specifically targeted by the hackers.

But I would not consider that list to be complete. Which is why you should replace your router if it factory reset remotely. Consider this a today problem.

The Director Of The FBI Has Had His Email Pwned By Iranian Hackers

Posted in Commentary with tags , , on March 30, 2026 by itnerd

The Iranian hacker group Handala has claimed another victim. After pwning this company, Handala has now apparently pwned the personal email account of FBI director Kash Patel. Cybernews suggests that this is in revenge for the FBI taking down the group’s leak site.

“Today, once again, the world witnessed the collapse of America’s so-called security legends. While the FBI proudly seized our domains and immediately announced a $10 million reward for the heads of Handala Hack members, we decided to respond to this ridiculous show in a way that will be remembered forever,” the group wrote on its new leak site.

“All personal and confidential information of Kash Patel, including emails, conversations, documents, and even classified files, is now available for public download” Handala claimed, also boasting about the alleged “get” on its now 42nd Telegram channel.

The posted samples include nine personal photos of Patel and an alleged resume belonging to the FBI head.

The FBI has basically admitted that this is real, and if you’re Patel or the FBI, this has to be highly embarrassing. But honestly, I think that’s the least of their problems. Handala is clearly on a rampage and I fully expect to see more pwnage from this group over the coming weeks seeing as they are an Iran aligned group and will likely want to “flex” for those in the Iranian regime who back them.