Threats Feed
- Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive
APT-C-49 (OilRig), an Iranian state-sponsored threat group, recently launched a sophisticated phishing campaign utilizing Iranian protest-themed Excel lures. Targeting government, finance, energy, telecommunications, and military sectors across the Middle East, US, Europe, and Asia, the group deployed a highly covert, multi-stage attack chain. The infection begins with macro-driven C# compilation, progressing to dead-drop resolving via GitHub. The payload utilizes LSB steganography on Google Drive-hosted images to extract encrypted configurations. Subsequently, it dynamically loads fileless modules into memory for data theft and remote execution, leveraging the Telegram Bot API for encrypted command and control (C2). This campaign highlights OilRig's evolution toward cloud service abuse and in-memory execution to evade detection.
read more about Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive - Public
OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.
read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Dust Specter: Iran-Nexus APT Targets Iraqi Government via Custom .NET Malware
In January 2026, the Iran-nexus threat actor Dust Specter launched a targeted cyber espionage campaign against Iraqi government officials, specifically impersonating the Ministry of Foreign Affairs. Utilizing compromised government infrastructure, the group deployed undocumented .NET-based malware, including the SPLITDROP dropper and the TWINTASK/TWINTALK backdoors. The operation is characterized by sophisticated DLL side-loading techniques using legitimate binaries like VLC and WingetUI. A secondary attack chain features GHOSTFORM, a consolidated RAT that employs invisible Windows forms for delayed execution and in-memory PowerShell scripts to minimize its forensic footprint. Evidence suggests the actors leveraged generative AI to streamline code development and implemented "ClickFix" social engineering tactics to compromise targets.
read more about Dust Specter: Iran-Nexus APT Targets Iraqi Government via Custom .NET Malware - Public
BladedFeline Targets Iraq and Kurdistan Governments with Custom Malware Arsenal
BladedFeline, an Iran-aligned APT group likely linked to OilRig (APT34), has conducted a multi-year cyberespionage campaign targeting Kurdish and Iraqi government officials as well as a telecommunications provider in Uzbekistan. Active since at least 2017, the group deployed various custom tools—including the Shahmaran and Whisper backdoors, the PrimeCache IIS module, reverse tunnels (Laret and Pinar), and several post-compromise implants—to maintain long-term access. Whisper abuses Microsoft Exchange email infrastructure for covert C2, while PrimeCache leverages malicious IIS components. This activity highlights Iran’s strategic interest in regional political and telecommunications sectors.
read more about BladedFeline Targets Iraq and Kurdistan Governments with Custom Malware Arsenal - Public
APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors
APT34 (OilRig) has launched a targeted cyber espionage campaign against Iraqi government entities since 2024, using spearphishing emails with forged documents to deploy custom C# malware disguised as PDF files. The malware performs system reconnaissance, anti-VM checks, and sets up persistence via scheduled tasks. It communicates with command-and-control infrastructure through both HTTP and compromised Iraqi government email accounts (SMTP/IMAP). The group also utilizes European-hosted infrastructure with deceptive 404 pages and obfuscated communication protocols. Targeted sectors include government, energy, finance, defense, and telecommunications, indicating a continued focus on intelligence gathering in the Middle East.
read more about APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors - Public
APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors
APT34 (OilRig) has launched a targeted cyber espionage campaign against Iraqi government entities since 2024, using spearphishing emails with forged documents to deploy custom C# malware disguised as PDF files. The malware performs system reconnaissance, anti-VM checks, and sets up persistence via scheduled tasks. It communicates with command-and-control infrastructure through both HTTP and compromised Iraqi government email accounts (SMTP/IMAP). The group also utilizes European-hosted infrastructure with deceptive 404 pages and obfuscated communication protocols. Targeted sectors include government, energy, finance, defense, and telecommunications, indicating a continued focus on intelligence gathering in the Middle East.
read more about APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors - Public
APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors
APT34 (OilRig) has launched a targeted cyber espionage campaign against Iraqi government entities since 2024, using spearphishing emails with forged documents to deploy custom C# malware disguised as PDF files. The malware performs system reconnaissance, anti-VM checks, and sets up persistence via scheduled tasks. It communicates with command-and-control infrastructure through both HTTP and compromised Iraqi government email accounts (SMTP/IMAP). The group also utilizes European-hosted infrastructure with deceptive 404 pages and obfuscated communication protocols. Targeted sectors include government, energy, finance, defense, and telecommunications, indicating a continued focus on intelligence gathering in the Middle East.
read more about APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors - Public
APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors
APT34 (OilRig) has launched a targeted cyber espionage campaign against Iraqi government entities since 2024, using spearphishing emails with forged documents to deploy custom C# malware disguised as PDF files. The malware performs system reconnaissance, anti-VM checks, and sets up persistence via scheduled tasks. It communicates with command-and-control infrastructure through both HTTP and compromised Iraqi government email accounts (SMTP/IMAP). The group also utilizes European-hosted infrastructure with deceptive 404 pages and obfuscated communication protocols. Targeted sectors include government, energy, finance, defense, and telecommunications, indicating a continued focus on intelligence gathering in the Middle East.
read more about APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors - Public
OilRig: Cyber-Espionage Targeting Global Critical Sectors
SOCRadar's January 2025 dark web profile on OilRig (APT34) documents the group as one of Iran's most persistent and sophisticated state-sponsored threat actors, active since at least 2016. OilRig targets government agencies, energy and oil & gas companies, telecommunications providers, financial institutions, universities, and research institutions — primarily across the Middle East, with confirmed extensions to Europe, North America, and Asia. The group follows a full kill chain methodology: reconnaissance using Netstat and Systeminfo; weaponization with custom tools including BondUpdater and Helminth; spearphishing delivery via email attachments, links, and LinkedIn (T1566.001/002/003); exploitation via Mimikatz for credential dumping and CVE-2017-11774 to abuse Outlook Home Page for persistence; C2 via DNS tunneling, encrypted channels, and fallback HTTP; and exfiltration over FTP (T1048.003). Post-compromise tools include LaZagne, ISMInjector, BONDUPDATER, PAExec, KEYPUNCH, LONGWATCH, VALUEVAULT, PICKPOCKET, and GOLDIRONY. OilRig also abuses Plink for tunnel creation and uses web shells for persistence. In destructive operations, the group has deployed ZeroCleare — a disk-wiping malware — demonstrating capability beyond espionage. The group regularly updates its toolset and evades detection through base64 obfuscation, AV testing, file deletion, and domain generation algorithms. OilRig's targeting aligns consistently with Iranian geopolitical and economic interests.
read more about OilRig: Cyber-Espionage Targeting Global Critical Sectors - Public
OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks
OilRig (APT34) has targeted the government, technology and energy sectors across the Middle East. Its operations include spearphishing campaigns, PowerShell-based backdoors (Helminth, QUADAGENT), and exploitation of vulnerabilities such as CVE-2024-30088. The group relies on obfuscation techniques to evade detection and uses tools such as STEALHOOK for privilege escalation, lateral movement and data exfiltration. Key targets include Saudi Arabian organisations and Middle Eastern government agencies, highlighting OilRig's focus on geopolitical intelligence gathering. The campaigns demonstrate advanced persistence, stealth and adaptability in line with state-sponsored objectives.
read more about OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks - Public
Earth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage
Earth Simnavaz, also known as APT34 or OilRig, has been targeting governmental entities in the UAE and Gulf region, focusing on the energy sector and critical infrastructure. The group uses sophisticated tactics, including the exploitation of Microsoft Exchange servers for credential theft and privilege escalation via CVE-2024-30088. They employ custom .NET tools, PowerShell scripts, and IIS-based malware to avoid detection. Additionally, the attackers utilize ngrok for persistent access and lateral movement, and manipulate password filters to extract plain-text credentials. These credentials are used for supply chain attacks, with a focus on exfiltrating sensitive data through compromised email servers.
read more about Earth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage - Public
UNC1860 Targets Middle Eastern Networks with Specialized Tooling
UNC1860, an Iranian state-sponsored group likely affiliated with the Ministry of Intelligence and Security (MOIS), targets government and telecommunications sectors in the Middle East, particularly in Saudi Arabia, Qatar, and Israel. The group acts as an initial access provider, exploiting vulnerabilities in internet-facing servers and deploying web shells like STAYSHANTE. Custom tools, such as TEMPLEPLAY and VIROGREEN, allow for remote access and further exploitation. UNC1860's operations are characterised by passive backdoors, credential validation, and stealthy malware that facilitates long-term persistence and hand-off to other threat actors. It's likely that the group has supported disruptive campaigns in the region.
read more about UNC1860 Targets Middle Eastern Networks with Specialized Tooling - Public
Veaty and Spearal Malware Used in Targeted Iraqi Government Attacks
Check Point Research has discovered new malware, Veaty and Spearal, used in Iran-linked cyber attacks against Iraqi government infrastructure. The malware uses techniques such as passive IIS backdoors, DNS tunneling, and compromised email accounts for C2 communications. The attackers also used social engineering tactics and double-extension files to trigger infections. Spearal communicates via DNS queries, while Veaty uses compromised email accounts within the gov-iq.net domain. The campaign targets Iraqi government agencies with ties to the APT34 group, demonstrating a sophisticated and persistent threat to Iraqi infrastructure.
read more about Veaty and Spearal Malware Used in Targeted Iraqi Government Attacks - Public
Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns
The Menorah malware, used by the APT34 threat group to target organisations in the Middle East, creates a mutex to ensure single-instance operation. The malware exfiltrates data and executes commands from a hardcoded command and control (C2) server. These commands include creating processes, listing files, downloading files and exfiltrating arbitrary data. The analysis provides technical details, including SHA256 hashes, mutex identifiers and the address of the C2 server, to aid detection and response efforts.
read more about Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns - Public
Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack
Crambus launched a sophisticated attack involving multiple malware strains, including three new ones: Tokel, Dirps, and Infostealer.Clipog, along with the known PowerExchange backdoor. The malware provided a wide range of functionalities from executing arbitrary PowerShell commands to information stealing and email monitoring. Living-off-the-land tools like Mimikatz and Plink were also deployed to dump credentials and configure port-forwarding for RDP access, respectively. The attackers displayed an advanced level of evasion, execution, and command-and-control techniques. The malicious activities spanned over several months, indicating a well-coordinated and persistent attack strategy.
read more about Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack - Public
APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia
Trend Micro researchers identified APT34 using a new custom backdoor named Menorah — a .NET-based malware delivered via a malicious Word document ("MyCv.doc") disguised as a Seychelles government license registration form. The document contained hidden macros that dropped Menorah into the system's %ALLUSERSPROFILE%\Office365 directory and established persistence through a scheduled task named "OneDriveStandaloneUpdater." Once installed, Menorah fingerprinted the victim machine using a hashed combination of machine name and username, communicated with a remote C2 server over HTTP using Base64-encoded, XOR-obfuscated traffic, and supported commands for file listing, selective file upload, shell command execution, and file download. The pricing in the lure document was denominated in Saudi Riyal, strongly suggesting the targeted victim was an organization in Saudi Arabia. Trend Micro noted functional similarities to APT34's earlier SideTwist backdoor, particularly in C2 communication and machine fingerprinting logic, though Menorah is a .NET reimplementation with enhanced sandbox evasion and traffic obfuscation.
read more about APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia - Public
APT34 Targets U.S. Enterprises with New SideTwist Trojan Variant
APT34 has launched a new phishing campaign, using a decoy file named “GGMS Overview.doc” to target U.S.-based enterprises. The campaign employs a variant of the SideTwist Trojan for long-term control over victim hosts. Malicious macros in the document deploy the Trojan, which communicates with a C&C server. Interestingly, the C&C IP address is associated with the United States Department of Defense Network Information Center. The Trojan is capable of executing commands from the C&C and exfiltrating local files. It suggests the APT34 group might be conducting a test operation to preserve attack resources.
read more about APT34 Targets U.S. Enterprises with New SideTwist Trojan Variant - Public
PowerExchange Campaign: APT34's Persistent Threat to UAE Government
The PowerExchange campaign, attributed to APT34, targeted Microsoft Exchange servers of a UAE government entity using a PowerShell backdoor. Delivered via phishing emails, the backdoor used the MicrosoftEdgeUpdateService for persistence, enabling frequent execution. The attackers used the Exchange Web Services API for command-and-control, deploying further payloads like Invoke-TheHash modules for lateral movement and webshells for credential harvesting.
read more about PowerExchange Campaign: APT34's Persistent Threat to UAE Government - Public
APT34 Suspected in Coordinated Attack on UAE Government Infrastructure
FortiEDR's research lab discovered a series of attacks on a government entity in the United Arab Emirates. The attacks involved a novel PowerShell-based backdoor dubbed PowerExchange. The backdoor's command and control (C2) protocol used the victim's Exchange server for communication. Further investigations revealed additional implants and a new web shell named ExchangeLeech that could harvest credentials. Iranian threat actor APT34 is suspected to be behind the attacks, which involved phishing emails for initial access, lateral movement within the network, and using scheduled tasks for persistence.
read more about APT34 Suspected in Coordinated Attack on UAE Government Infrastructure