Threats Feed
- Public
CharmPower: APT35's Modular Toolset Exploits Log4j Vulnerability
APT35 has started widespread scanning and attempts to leverage the Log4j flaw in publicly facing systems only four days after the vulnerability was disclosed. The group used a modular PowerShell-based framework dubbed CharmPower for persistence, information gathering, and command execution.
read more about CharmPower: APT35's Modular Toolset Exploits Log4j Vulnerability - Public
Memento Team's Innovative Ransomware Strategy: Bypassing Encryption Detection
Sophos discovered a novel ransomware approach by "Memento Team," which bypasses encryption detection by copying files into password-protected archives. Initially attempting direct encryption thwarted by endpoint protection, the actors retooled their method. They demanded $1 million for file restoration, threatening data exposure. The attack exploited a VMware vCenter Server vulnerability, with the attackers gaining initial access through a misconfigured firewall. Their activities included lateral movement using stolen credentials and deployment of a Python-based keylogger. The attack leveraged various tools like WinRAR, Mimikatz, and PowerShell, culminating in file archiving for ransom. The targeted sectors or countries were not specified in the report.
read more about Memento Team's Innovative Ransomware Strategy: Bypassing Encryption Detection - Public
APT35 Cyber Espionage: From Phishing to Spyware and Beyond
APT35 has used multiple tactics to compromise high-value targets. The group has used hijacked websites, such as one affiliated with a UK university, for credential phishing attacks. They have also uploaded spyware disguised as VPN software to app stores and impersonated conference officials to conduct phishing campaigns. Additionally, APT35 has utilized link shorteners and click trackers embedded within PDF files and abused services like Google Drive, App Scripts, and Sites pages. The group has adopted a novel approach by leveraging Telegram for real-time operator notifications, enabling them to monitor visitor information to their phishing sites.
read more about APT35 Cyber Espionage: From Phishing to Spyware and Beyond - Public
Stealthy APT35 Activity in EMEA Corporate Environment
APT35, also known as Charming Kitten, had infiltrated an organization in the EMEA region. The infected corporate device was only engaged in command and control (C2) beaconing and showed no signs of lateral movement or data exfiltration. Despite a mature security stack, the organization was unaware of the infection until the new security measures were implemented.
read more about Stealthy APT35 Activity in EMEA Corporate Environment - Public
Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence
ClearSky's October 2019 report documented an active Charming Kitten (APT35/Phosphorus) campaign targeting US presidential campaign staff, government officials, journalists, Iranian dissidents, and civil society figures including the Baha'i community. The campaign used four distinct impersonation vectors: fake Google Drive sharing links, SMS phishing messages, spoofed account login-attempt alerts, and fake social network profiles impersonating known contacts. Malicious links led to credential-harvesting pages mimicking Google, Yahoo, Facebook, and Instagram logins, hosted on a network of actor-registered domains. The group abused Google Sites and URL shorteners to obfuscate malicious destinations. Microsoft identified 99 domains tied to the operation (tracked internally as Phosphorus/Strontium) and obtained a court order to seize them. IOC overlaps with prior Certfa reporting confirm continuity of infrastructure across Charming Kitten campaigns dating to 2018. The campaign is assessed as part of Iran's broader effort to conduct cyber-enabled political intelligence collection ahead of the 2020 US presidential election.
read more about Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence - Public
Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign
The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.
read more about Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign