Nazar
Named by Epic TurlaSuspected state sponsor: Islamic Republic of IranNazar is an Iranian-linked threat actor first identified in April 2020 by researcher Juan Andres Guerrero-Saade through analysis of the NSA's "Territorial Dispute" detection signatures leaked by the Shadow Brokers in 2017. Active since at least 2008, the group operated undetected by the security industry for over a decade, with the NSA having monitored it before 2013. All known Nazar subcomponent samples were submitted to VirusTotal from Iran, and Farsi language artifacts found in the malware's debug paths — including the term "khzer" meaning "to survey or monitor" — point to Iranian origin and likely domestic targeting. The group's modular toolkit includes a dropper that registers DLLs as OLE controls, an orchestrator disguised as svchost.exe, and components for screen capture, microphone recording, keylogging, and a passive network packet sniffer that monitors interface traffic for covert command and control. Check Point's subsequent analysis confirmed the toolkit's use of open-source libraries and assessed the code quality as below the standard of sophisticated state espionage groups, suggesting Nazar operated as a lower-tier surveillance capability possibly directed at targets inside Iran.
Targeted Regions
IranIran
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Oct 2009 ~ Apr 2020
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.