Threats Feed
- Public
Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.
read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign - Public
Iranian Chafer APT Targets Kuwait and Saudi Arabia’s Critical Sectors
Bitdefender's May 2020 whitepaper documents two Chafer APT campaigns dating to 2018 against air transportation and government targets in Kuwait and Saudi Arabia. The Kuwait attack was the more sophisticated of the two. Initial access was likely achieved via spearphishing with shellcode-laden documents executing Metasploit reverse TCP payloads. Attackers then deployed a full toolkit: CrackMapExec for network scanning, credential dumping, and account enumeration; Mimikatz (including a SafetyKatz variant and a customized version) for credential dumping; a modified Plink (wehsvc.exe) installed as a Windows service for C2 and tunneling; custom proxy tools (mini.exe, mfevtpse.exe) using SOCKS5 over HTTP disguised with bing.com host headers; and custom Python-based RATs (snmp.exe/imjpuexa.exe) using DNS and HTTP C2 channels that marshal packets to resemble legitimate DNS/HTTP traffic. A MechaFlounder-variant RAT (drivers.exe/dbxservice.exe) established persistence via scheduled tasks ("Defender Update" / "Service Update") and exfiltrated data to Dropbox — each victim had a separate folder named by machine+username combination. The RTLO character (U+202E) was used in filenames to spoof file extensions for defense evasion. Attackers created their own user accounts on compromised machines and operated primarily on weekends (Friday/Saturday — the regional weekend), suggesting awareness of Middle Eastern business hours. Scanning tools included a modified nbtscan variant (xnet.exe) and etblscanner.exe, an EternalBlue scanner written in Python. Shared PDB paths and compiler artifacts link xnet.exe to Remexi (mas.dll), connecting this campaign to prior Chafer infrastructure. The Saudi Arabia attack was simpler: social engineering led a user to execute a RAT directly from their Downloads folder (parent process: explorer.exe), suggesting the user was tricked into double-clicking a malicious file.
read more about Iranian Chafer APT Targets Kuwait and Saudi Arabia’s Critical Sectors - Public
The Invisible Threat: Chafer's Advanced Backdoor Malware Analysis
The report provides a comprehensive analysis of a 64-bit backdoor executable associated with the Chafer APT group. The malware utilizes complex features such as process injection, task scheduling, and data obfuscation, along with automated exfiltration of information. It communicates with its C2 server via POST requests and employs encryption algorithms like RC4 and Blowfish to conceal its data and operations. Unusually, it masquerades by creating CAB files with non-standard prefixes and encrypting data in a manner that appears like a routine system operation.
read more about The Invisible Threat: Chafer's Advanced Backdoor Malware Analysis - Public
Unraveling MechaFlounder: Chafer's New Python-Based Tool Targets Turkey
In November 2018, the Iranian-linked Chafer threat group deployed a previously unseen Python-based backdoor called MechaFlounder against a Turkish government entity — marking the first confirmed use of a Python payload by this actor. The malware was compiled into a standalone executable using PyInstaller, allowing it to run on target systems without requiring a Python interpreter and making it harder to identify through file-type signatures alone. It was delivered from a malicious domain directly tied to prior Chafer infrastructure, indicating deliberate reuse of established operational resources. MechaFlounder functions as a fully capable remote access tool, supporting file upload and download, command execution, and C2 communication over HTTP using Base64-encoded data. Palo Alto Networks analysts noted that portions of MechaFlounder's code overlap with tooling associated with OilRig, a separate Iranian-linked threat group, suggesting a degree of code sharing or shared development resources between the two actors.
read more about Unraveling MechaFlounder: Chafer's New Python-Based Tool Targets Turkey - Public
Chafer APT Targets Iranian Diplomatic Entities with Updated Remexi Malware
Throughout autumn 2018, Kaspersky researchers identified an active cyber-espionage campaign attributed to the Iran-based Chafer group, targeting foreign diplomatic entities operating inside Iran. The attackers deployed an updated version of Backdoor.Remexi — a Windows trojan capable of logging keystrokes, capturing screenshots, stealing browser credentials and history, and executing remote commands. The malware relied heavily on Microsoft's Background Intelligent Transfer Service (BITS) for both receiving commands and exfiltrating collected data, blending malicious traffic with legitimate Windows activity. Persistence was maintained through scheduled tasks and registry modifications. Encryption used XOR and RC4 algorithms with unique per-sample keys; one sample used the Farsi word for "health" as a key, reinforcing Iranian attribution. Kaspersky assessed the campaign as a likely domestic counter-intelligence operation.
read more about Chafer APT Targets Iranian Diplomatic Entities with Updated Remexi Malware - Public
Chafer's Rising Ambitions: New Tools and Tactics in the Cyber Threat Landscape
The Iran-based attack group, Chafer, escalated operations in 2017, striking more organizations within and beyond the Middle East. Utilizing several new tools, they targeted sectors including airlines, telecoms services, and IT services for transport sectors among others. Chafer sought to infiltrate a major telecoms services provider and an international travel reservations firm, likely aiming for widespread surveillance. The group employed malicious documents, SQL injection attacks, and newly adopted open-source tools to compromise targets. These activities indicate a growing threat, especially as Chafer shows a rising trend in attacks on supply chains.
read more about Chafer's Rising Ambitions: New Tools and Tactics in the Cyber Threat Landscape - Public
Chafer and Cadelle: Unveiling Iran's Persistent Cyber Surveillance on Middle Eastern Targets
Symantec researchers identified two Iran-based threat groups, Cadelle and Chafer, conducting targeted surveillance operations against individuals and organizations in Iran and across the Middle East. Active since at least July 2014, the groups deployed custom-built backdoor malware — Backdoor.Cadelspy and Backdoor.Remexi — capable of keystroke logging, audio recording, screen capture, and remote command execution. Their primary targets included telecommunications providers and airlines in the Middle East, likely to monitor the movements and communications of persons of interest. Symantec assessed that the attackers operated during Iranian business hours, and that their victim profile aligns with the intelligence interests of an Iranian state entity. Both groups were confirmed to still be active at the time of publication.
read more about Chafer and Cadelle: Unveiling Iran's Persistent Cyber Surveillance on Middle Eastern Targets