Latest Update27/08/2026

Threats Feed

  1. Public

    Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide

    Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.

    read more about Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide
  2. Public

    Iranian APT Charming Kitten Mimics ClearSky in Phishing Scheme

    The Iranian APT group Charming Kitten impersonated Israeli cybersecurity firm ClearSky by creating a phishing website that mimicked the legitimate Clearskysec.com domain. The fake site, hosted on an older compromised server, replicated ClearSky's public web pages and included phishing login options to harvest credentials. ClearSky identified the incomplete site, which was taken down before it could affect any victims. Charming Kitten has previously targeted academic researchers, human rights activists, media outlets and political consultants in Iran, the US, UK and Israel. Known for spear-phishing, impersonating organisations, and deploying malware such as DownPaper, this campaign underscores the ongoing threat to security researchers and geopolitical targets.

    read more about Iranian APT Charming Kitten Mimics ClearSky in Phishing Scheme
  3. Public

    Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

    Beginning in late 2016, Shamoon 2.0 and the newly discovered StoneDrill malware launched destructive wiper attacks against critical and economic sectors in Saudi Arabia, with evidence of StoneDrill reaching European targets. Shamoon 2.0, a successor to the 2012 Saudi Aramco attack tool, incorporated stolen administrator credentials, automated worm-like spreading, disk wiping, and even inactive ransomware capabilities. StoneDrill introduced advanced sandbox evasion, injected its payload into browsers, and targeted accessible files or full disks. Both malware families used obfuscation, anti-analysis tricks, and in Shamoon’s case, signed drivers for low-level destruction. StoneDrill shared code similarities with the NewsBeef (aka Charming Kitten) APT, suggesting broader regional targeting and actor overlap.

    read more about Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets
  4. Public

    Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

    Beginning in late 2016, Shamoon 2.0 and the newly discovered StoneDrill malware launched destructive wiper attacks against critical and economic sectors in Saudi Arabia, with evidence of StoneDrill reaching European targets. Shamoon 2.0, a successor to the 2012 Saudi Aramco attack tool, incorporated stolen administrator credentials, automated worm-like spreading, disk wiping, and even inactive ransomware capabilities. StoneDrill introduced advanced sandbox evasion, injected its payload into browsers, and targeted accessible files or full disks. Both malware families used obfuscation, anti-analysis tricks, and in Shamoon’s case, signed drivers for low-level destruction. StoneDrill shared code similarities with the NewsBeef (aka Charming Kitten) APT, suggesting broader regional targeting and actor overlap.

    read more about Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets
  5. Public

    Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

    Beginning in late 2016, Shamoon 2.0 and the newly discovered StoneDrill malware launched destructive wiper attacks against critical and economic sectors in Saudi Arabia, with evidence of StoneDrill reaching European targets. Shamoon 2.0, a successor to the 2012 Saudi Aramco attack tool, incorporated stolen administrator credentials, automated worm-like spreading, disk wiping, and even inactive ransomware capabilities. StoneDrill introduced advanced sandbox evasion, injected its payload into browsers, and targeted accessible files or full disks. Both malware families used obfuscation, anti-analysis tricks, and in Shamoon’s case, signed drivers for low-level destruction. StoneDrill shared code similarities with the NewsBeef (aka Charming Kitten) APT, suggesting broader regional targeting and actor overlap.

    read more about Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets
  6. Public

    NewsBeef APT Revives BeEF for Global Watering Hole Campaigns

    In early 2016, the NewsBeef APT (aka Charming Kitten/Newscaster) repurposed the open-source BeEF and Metasploit frameworks in widespread watering hole attacks. These operations targeted visitors to strategically compromised websites, including institutions in Iran, Russia, India, Ukraine, the EU, Turkey, Germany, Japan, China, Brazil, and more. Sectors impacted included education, military, diplomacy, manufacturing, and media. The attackers injected malicious JavaScript to hook browsers, track visitor behavior, and fingerprint systems using evercookies and browser enumeration. While full exploitation wasn’t always observed, selective delivery of backdoors or spoofed login prompts was reported. The group’s campaign reflects an evolution from low-tech social engineering to more technically advanced infrastructure attacks using open-source tools.

    read more about NewsBeef APT Revives BeEF for Global Watering Hole Campaigns
  7. Public

    NewsBeef APT Revives BeEF for Global Watering Hole Campaigns

    In early 2016, the NewsBeef APT (aka Charming Kitten/Newscaster) repurposed the open-source BeEF and Metasploit frameworks in widespread watering hole attacks. These operations targeted visitors to strategically compromised websites, including institutions in Iran, Russia, India, Ukraine, the EU, Turkey, Germany, Japan, China, Brazil, and more. Sectors impacted included education, military, diplomacy, manufacturing, and media. The attackers injected malicious JavaScript to hook browsers, track visitor behavior, and fingerprint systems using evercookies and browser enumeration. While full exploitation wasn’t always observed, selective delivery of backdoors or spoofed login prompts was reported. The group’s campaign reflects an evolution from low-tech social engineering to more technically advanced infrastructure attacks using open-source tools.

    read more about NewsBeef APT Revives BeEF for Global Watering Hole Campaigns