Latest Update27/08/2026

Threats Feed

  1. Public

    Veaty and Spearal Malware Used in Targeted Iraqi Government Attacks

    Check Point Research has discovered new malware, Veaty and Spearal, used in Iran-linked cyber attacks against Iraqi government infrastructure. The malware uses techniques such as passive IIS backdoors, DNS tunneling, and compromised email accounts for C2 communications. The attackers also used social engineering tactics and double-extension files to trigger infections. Spearal communicates via DNS queries, while Veaty uses compromised email accounts within the gov-iq.net domain. The campaign targets Iraqi government agencies with ties to the APT34 group, demonstrating a sophisticated and persistent threat to Iraqi infrastructure.

    read more about Veaty and Spearal Malware Used in Targeted Iraqi Government Attacks
  2. Public

    OilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms

    OilRig targeted a telecommunications organization in the Middle East using a variant of their RDAT tool, featuring a novel email-based command and control (C2) channel that employs steganography. This method hides commands and data within bitmap images attached to emails, making detection difficult. The attack involved custom Mimikatz tools for credential dumping, Bitvise for SSH tunneling, and PowerShell downloaders. RDAT has been under development since 2017, evolving to include DNS tunneling and Exchange Web Services (EWS) for C2 communications. The use of steganographic images in emails represents a sophisticated evasion technique.

    read more about OilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms
  3. Public

    Greenbug's Cyber Espionage Campaign Against South Asian Telecoms

    The Greenbug espionage group is conducting an information-gathering campaign against telecommunications companies in South Asia. Using a mix of off-the-shelf tools and living-off-the-land techniques, the group primarily employs email as the initial infection vector. Notable files used for infection are proposal_pakistan110.chm:error.html and GRUNTStager.hta, often delivered through compromised websites via spearphishing. The group aims to gain access to database servers, leveraging tools like Covenant and custom malware like Trojan.Ismdoor. They have been observed using various PowerShell commands, Mimikatz, and Cobalt Strike, alongside multiple webshells. Living-off-the-land utilities such as Plink and Bitvise were used to establish tunnels back to attacker-controlled infrastructure.

    read more about Greenbug's Cyber Espionage Campaign Against South Asian Telecoms
  4. Public

    Decoding Greenbug Group's Command and Control Communications via DNS Tunneling

    DomainTools demonstrates how passive DNS pivoting on ISMDoor's static IPv6 response fingerprints can be used to systematically discover Greenbug's C2 infrastructure — including domains not previously reported. The analysis confirms ISMDoor remained active as recently as November 2019, more than two years after the malware's initial public disclosure in 2017. By querying passive DNS for four known static IPv6 addresses returned during ISMDoor's session establishment protocol (a67d:db8:a2a1:7334:7654:4325:370:2aa3, a67d:db8:85a3:4325:7654:8a2a:370:7334, the all-spaces address 2020:2020:..., and the "Ok" response 4f6b:2020:...), DomainTools identified 19 C2 domains across old and current infrastructure. Most were already sinkholed, but winrepp[.]com was still active on Digital Ocean at the time of publication. Pivoting from that IP and then from outbrainsecupdater[.]com revealed an additional 37 associated domains, including microsoft-publisher[.]com confirmed as an ISMDoor C2 through captured AAAA query data. The report notes that Greenbug's use of DNS tunneling remains effective because many organizations do not monitor DNS traffic for behavioral anomalies. The static IPv6 fingerprints embedded in ISMDoor's session establishment provide a durable detection opportunity regardless of which C2 domain the malware uses — a technique DomainTools notes can be applied to hunt for other DNS-tunneling malware families as well.

    read more about Decoding Greenbug Group's Command and Control Communications via DNS Tunneling
  5. Public

    How the GreenBug Group Exploits DNS Tunneling with Ismdoor Malware

    The Ismdoor malware, linked with the GreenBug group, continues its cyberattacks using DNS tunneling to evade detection, communicate with command and control servers, and exfiltrate data. Black Lotus Labs detected recent spikes in such activities related to the domain basnevs[.]com, associated with Ismdoor. The malware uses encoded subdomains for data exfiltration and receives hex-encoded messages from the C2. An increase in tunneling activity suggests that too many organizations still allow unmonitored DNS traffic, which amplifies the risk of successful DNS tunneling attacks. The report doesn't explicitly mention specific targeted countries or sectors.

    read more about How the GreenBug Group Exploits DNS Tunneling with Ismdoor Malware
  6. Public

    APT34's Phishing Strategy With New Malware Families Targeting Key Sectors

    Mandiant detected a phishing campaign by APT34, an Iranian-nexus threat actor, in late June 2019. The actor, posing as a member of Cambridge University, delivered malicious documents via LinkedIn and introduced three new malware families. The primary industries targeted by this campaign were Energy and Utilities, Government, and Oil and Gas. APT34 is notably active in the Middle East, employing a blend of public and non-public tools to carry out its cyber espionage activities.

    read more about APT34's Phishing Strategy With New Malware Families Targeting Key Sectors
  7. Public

    Potential Cyber Targets Revealed in Greenbug's Domain Registrations: Israeli and Saudi Firms in Focus

    The Iranian threat agent Greenbug registered domains similar to Israeli high-tech and cybersecurity companies, as well as a Saudi Arabian electrical equipment firm. A sample of the ISMdoor malware was submitted from Iraq on October 15, 2017, indicating the threat actor's activities. Despite these registrations, no evidence of direct targeting or impact on these companies is present. High-tech, cybersecurity, online advertising, airport security systems, web development, behavioral biometrics, artificial intelligence, data security, and autonomous driving are sectors potentially of interest to the actor.

    read more about Potential Cyber Targets Revealed in Greenbug's Domain Registrations: Israeli and Saudi Firms in Focus
  8. Public

    The Base64 Disguise: How GreenBug's Trojan ISMAgent Evades Detection

    ClearSky Research Team documents new ISMAgent samples and infrastructure used by the Iranian threat group Greenbug in August 2017. The delivery chain begins with a malicious Word template file named "change managment.dot" that exploits CVE-2017-0199, a remote code execution vulnerability in Microsoft Office. Exploiting this vulnerability causes the document to reach out to msoffice-cdn[.]com and retrieve a remote template (template.rtf), which in turn executes a hidden PowerShell command. The PowerShell command downloads a file called ntluca.txt from a.pomf[.]cat — a file that appears to be a base64-encoded digital certificate but is actually an ISMAgent payload. The file is decoded on disk using the legitimate Windows utility certutil.exe, producing the ISMAgent executable (srvConhost.exe) which is then run silently. ClearSky provides a Maltego-based infrastructure graph mapping the relationships between the IOCs, including C2 IPs (74.91.19[.]122, 82.102.14[.]246, 185.162.235[.]121), domains (cdnmsnupdate[.]com, msoffice-cdn[.]com), and WHOIS registrant data (neslihan.ovcivit@mail.ru). Several of these IOCs overlap with OilRig infrastructure documented in a concurrent Palo Alto Networks report, suggesting shared or coordinated infrastructure between the two Iranian-linked groups. Source URL is no longer directly accessible; this analysis is based on the archived PDF attachment.

    read more about The Base64 Disguise: How GreenBug's Trojan ISMAgent Evades Detection
  9. Public

    Greenbug Group's Escalated Threat: Ismdoor RAT's Role in the Shamoon Attacks

    NETSCOUT's ASERT team documents a significant evolution in Ismdoor, the custom remote access trojan used by the Iranian-linked Greenbug cyberespionage group. Where earlier versions used HTTP for command and control, the versions analyzed here replaced that entirely with a covert DNS-based C2 channel — communicating exclusively through AAAA DNS queries, encoding data as IPv6 addresses. The protocol is multi-layered: sessions are established via specially formatted query names containing a 32-character hex session ID, messages are base64-encoded and embedded in query subdomains, and responses are returned as static or data-carrying IPv6 addresses. File transfers use a separate session type with retransmission logic for missed packets. The malware supports over 20 C2 commands, including system information collection, self-update, credential dumping via Mimikatz (CreateMimi1Bat command invoking ccd61.ps1), keylogging (ExecuteKL), Powercat execution for network tunneling (ExecutePC), UAC bypass via RAAD, screenshot capture (PWS), and arbitrary command shell execution. Configuration is encrypted with a consistent substitution cipher and contains primary and secondary C2 domains, timeout values, and a unique bot identifier. NETSCOUT presents four indicators linking Ismdoor to the Shamoon/Disttrack campaigns against Saudi Arabia: Symantec observed an earlier Ismdoor variant on a Shamoon-targeted host shortly before Disttrack was deployed; all known DNS-variant samples were submitted to VirusTotal from Saudi Arabia; the CreateMimi1Bat command provides explicit credential-theft capability; and a McAfee blog on Shamoon traces a spearphishing email to the download and execution of an earlier Ismdoor variant. The link remains assessed as probable but unconfirmed at time of publication.

    read more about Greenbug Group's Escalated Threat: Ismdoor RAT's Role in the Shamoon Attacks
  10. Public

    Unraveling Greenbug Group's RAT: Keylogging, Powercat, and Beyond

    NCC Group's Ahmed Zaki provides the first detailed technical analysis of ISM RAT (Ismdoor) version 5.0.0, the HTTP-based variant used by the Greenbug group before the group later switched to DNS tunneling. NCC identifies three versions of the RAT in the wild; v5.0.0 is the most capable, adding keylogging (WinIt.exe), Powercat-based shell access on port 4444, Mimikatz credential dumping, and UAC bypass via Invoke-BypassUAC and Invoke-PsUACme — the latter suspected to be from the Nishang PowerShell framework. All C2 communication uses HTTP POST requests to update.winappupdater[.]com with a WinHTTPClient user agent; key endpoints include /Home/CC (connection check), /Home/CR (command receive), /Home/AV (alive), and /Home/SCV (command result reporting). The SI command collects extensive system reconnaissance: username, IP configuration, network connections, running tasks, services, and installed AV/firewall products via WMIC — all written to a temporary .txt file and exfiltrated. NCC notes that the RAT's authors copy-pasted WinHTTP code directly from MSDN examples, left debugging messages in release builds, and used an unusual method to retrieve %TEMP% via a command prompt rather than the standard Windows API — leading the analysts to conclude the group is not technically sophisticated despite the breadth of their tooling. The RAT uses timer-queue callbacks for thread management and is assessed to be under active development given ongoing code refactoring and the introduction of versioning. Source URL is no longer accessible; this analysis is based on the archived PDF attachment.

    read more about Unraveling Greenbug Group's RAT: Keylogging, Powercat, and Beyond
  11. Public

    The Possible Connection Between Greenbug and Shamoon Revealed

    The Greenbug cyberespionage group, active since June 2016, has been using Trojan.Ismdoor, a custom information-stealing remote access Trojan (RAT), and additional hacking tools to compromise organizations in the Middle East and a Saudi organization in Australia. The group targets sectors including aviation, energy, government, investment, and education, using spearphishing emails to deliver malicious payloads hidden in RAR archives. Once opened, the Trojan opens a backdoor and collects sensitive data, potentially facilitating further attacks. Notably, the group’s activity ceased a day before the destructive W32.Disttrack.B (Shamoon) attack in November 2016, suggesting a possible connection.

    read more about The Possible Connection Between Greenbug and Shamoon Revealed