Threats Feed
- Public
Mermaid APT: A Continuing Threat to Government Agencies
The Mermaid (Infy, Prince of Persia) APT organization, primarily targeting government agencies, has been active since 2010 with consistent attacks and no significant operational gaps. Originating from the Middle East, they utilize the Infy backdoor, evolving into the Foudre backdoor by 2017. The group employs documents with malicious macros, embedding OLE objects to execute the Foudre backdoor via social engineering. Techniques include keylogging, registry modification, scheduled tasks for persistence, and using rundll32 for process injection. The attack also involves substantial data concealment with compressed files and web protocol communication for C2 interactions. The report indicates a sophisticated approach in both evading detection and maintaining long-term access to targeted systems.
read more about Mermaid APT: A Continuing Threat to Government Agencies - Public
Operation Mermaid: A Decade of Targeted APT Attacks on Government Entities
Operation Mermaid, an APT campaign active since April 2010, targeted government entities, specifically the Denmark Embassy and the Ministry of Foreign Affairs of Denmark. This six-year operation utilized phishing emails and watering hole attacks to deliver malicious code, evidenced by 284 malicious samples and 35 C&C domains. Analysis revealed the primary aim was data theft from English and Persian speaking countries. The SD RAT malware, disguised as legitimate files, played a key role in these attacks, featuring keylogging and data exfiltration capabilities. Differences in malware versions and tactics, including a unique check for Avast antivirus, suggest evolving strategies to evade detection.
read more about Operation Mermaid: A Decade of Targeted APT Attacks on Government Entities