Threats Feed
- Public
APT34 Targets Jordan's Government with Saitama Backdoor: A New Wave of Cyber Espionage
Malwarebytes Threat Intelligence documents the discovery of Saitama, a new APT34 backdoor found in a spearphishing attack on April 26, 2022 against a government official at Jordan's Foreign Ministry. The malicious email was sent from a Microsoft Outlook account impersonating a Jordanian government official — using the Jordan coat of arms as a signature — with an Excel attachment named "Confirmation Receive Document.xls." The macro runs on WorkBook_Open(), uses a WMI Win32_PingStatus query (rather than standard DNS resolution) to beacon execution steps to the C2, implements a mouse-check anti-sandbox technique (only executing if a mouse is detected), creates a %APPDATA%/MicrosoftUpdate directory, writes three payload components (Update.exe, Update.exe.config, Microsoft.Exchange.WenServices.dll) decoded from Base64 UserForm labels, and establishes persistence via a scheduled task named "MicrosoftUpdate." The Saitama backdoor (PDB: E:\Saitama\Saitama.Agent\obj\Release\Saitama.Agent.pdb) is a .NET finite state machine with states: BEGIN, ALIVE (fetches C2 via PRNG-seeded Mersenne Twister subdomains), SLEEP/SECOND SLEEP (up to 6–8 hours on failed DNS), RECEIVE, DO, and SEND/SEND AND RECEIVE. Its 22 hardcoded predefined commands include network reconnaissance (whoami, net user, hostname, systeminfo, TCP connections, DNS server addresses) alongside internal IP ping sweeps and nslookup queries targeting internal Jordanian government FQDNs (ise-posture.mofagov.gover.local, webmail.gov.jo), confirming prior knowledge of the victim network. Attribution to APT34 rests on maldoc similarities with prior APT34 campaigns (including the same mouse anti-sandbox and ENotif beacon pattern), Jordan government targeting history, and DNS C2 with Base32/Base36 encoding consistent with DNSpionage and prior Mandiant-reported APT34 campaigns.
read more about APT34 Targets Jordan's Government with Saitama Backdoor: A New Wave of Cyber Espionage - Public
Iranian APT34's Evolving Arsenal: A Deep Dive into the SideTwist Campaign
The article from Check Point Research focuses on the resurgence of Iran's APT34 cyber espionage group, which has updated its tactics and tools. This group, also known as OilRig, has targeted a Lebanese entity using a new backdoor variant named "SideTwist". They have refined their strategies to evade detection, continuing their pattern of using job opportunity documents to deliver malware through LinkedIn. The article provides an in-depth analysis of the infection chain, the malware's capabilities, and its persistence techniques. It aligns with APT34's history of targeting Middle Eastern entities, underscoring the ongoing cyber threats in the region.
read more about Iranian APT34's Evolving Arsenal: A Deep Dive into the SideTwist Campaign - Public
OilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms
OilRig targeted a telecommunications organization in the Middle East using a variant of their RDAT tool, featuring a novel email-based command and control (C2) channel that employs steganography. This method hides commands and data within bitmap images attached to emails, making detection difficult. The attack involved custom Mimikatz tools for credential dumping, Bitvise for SSH tunneling, and PowerShell downloaders. RDAT has been under development since 2017, evolving to include DNS tunneling and Exchange Web Services (EWS) for C2 communications. The use of steganographic images in emails represents a sophisticated evasion technique.
read more about OilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms - Public
APT34 Strikes Lebanese Government with MailDropper Implant
Telsy's threat intelligence team provides the most detailed technical analysis of the MailDropper implant used by APT34 against Lebanese government entities in early 2020, published simultaneously with Yoroi's parallel report on the same sample. The infection begins with a spearphishing Excel document containing a VBA macro that drops monitor.exe into a hidden .Monitor folder under C:\Users\Public\. A scheduled task named "SystemErrorReporter" runs the payload every minute. The monitor.exe binary contains hardcoded credentials for a compromised Exchange account (redacted as media@xxx.local) belonging to the targeted Lebanese government institution. Commands are retrieved by polling the Exchange Inbox for emails with the subject "Resume7AKF1PMAVAHI7SYK"; matching emails have Base64-encoded command payloads in their attachments, which are extracted and executed via ExecAllCmds. After processing, each email is permanently deleted with the HardDelete flag — ensuring processed commands leave no trace in the trash folder. Results are returned as new emails with subject "Great! 7AKF1PMAVAHI7SYK" + date, body "This is our reusme!" (syntax error preserved as a forensic indicator), with command output base64-encoded in an attachment named resume.txt. If the Exchange server is unavailable, MailDropper falls back to a backup HTTP C2 at godoycrus[.]com. All data exchanged with the C2 is encrypted using AES+RSA hybrid encryption: data is AES-encrypted with an auto-generated key, the key is then RSA-encrypted and prepended to the payload. Telsy draws four specific parallels to DNSpionage (Lebanon targeting, Excel macro delivery, dot-prefixed hidden folder, .NET payload) as supporting attribution to APT34. Telemetry at time of publication confirmed the implant was in use exclusively within Lebanon.
read more about APT34 Strikes Lebanese Government with MailDropper Implant - Public
APT34 Strikes Again: Government Sector in Lebanon Under Karkoff Attack
Yoroi (Cybaze ZLab) identifies an updated Karkoff implant used by APT34 in a new espionage campaign targeting the Lebanon government, active from at least January 27, 2020 — the date godoycrus[.]com was registered. The campaign connects to a 2018–2019 chain: Cisco Talos had documented the original DNSEspionage campaign against Lebanon and UAE, then in April 2019 linked it to APT34 and named the implant Karkoff. This 2020 variant introduces two key changes. First, it implements a reconnaissance guardrail: before dropping the final payload, Karkoff collects the hostname, domain name, and OS version and only proceeds if the target matches a specific profile — significantly reducing exposure to sandbox and automated analysis environments. Second, the C2 channel runs entirely through a compromised Lebanon government Microsoft Exchange server: Karkoff connects using an Exchange client UserAgent string, retrieves commands delivered as email attachments in replied messages, and decodes them from a custom-encoded email body string. Delivery begins with a malicious Excel macro (hash: 926e29f9...) that extracts a base64-encoded payload from the file body, decodes it, writes monitor.exe to C:\Users\public\.Monitor\, and establishes persistence via a scheduled task named SystemExchangeService. Yoroi assesses APT34 likely used the Jason brute-force tool — leaked in late 2019 and part of the Lab Dookhtegan APT34 tool dump — to obtain Exchange credentials before deploying Karkoff. Telsy published a parallel analysis of the same sample on the same day. Yoroi provides two YARA rules for detection: Karkoff_Attack_2020_Excel_macro (matching EncodedData0, NewTask9 strings) and Karkoff_Campaign_2020 (matching SystemExchangeService, getWindowsVersion, GetCommands). Source URL is no longer directly accessible; this analysis is based on the archived PDF attachment.
read more about APT34 Strikes Again: Government Sector in Lebanon Under Karkoff Attack - Public
APT34 Strikes Again: Advanced and Stealthy TONEDEAF 2.0 Targets US Research Services
APT34 has launched a new campaign targeting United States-based research services company Westat, and its customers, employing a modified toolset. The attack was discovered in late January 2020 and initiated with a spear-phishing operation using a disguised employee satisfaction survey file, survey.xls. Once the victim enabled macros, malicious VBA code executed, extracting and installing a more advanced and stealthy variant of the TONEDEAF malware, TONEDEAF 2.0. The attackers also possibly used a VALUEVAULT implant for browser credential theft. The effort demonstrates APT34's substantial investment in upgrading its toolset to evade future detection.
read more about APT34 Strikes Again: Advanced and Stealthy TONEDEAF 2.0 Targets US Research Services - Public
OilRig's Poison Frog: From PowerShell Backdoors to Cisco AnyConnect Disguises
Kaspersky's December 2019 report analyzes Poison Frog, a PowerShell-based backdoor used by OilRig (APT34) discovered after scanning archives with a custom YARA rule. The earliest samples date to July 2017, with the malware named after its C2 domain poison-frog[.]club. Each sample is a PE32 executable written in C# that drops an embedded PowerShell script containing two backdoor agents — an HTTP backdoor (59 lines) and a DNS backdoor (335 lines) — and deletes the dropper after execution. The HTTP agent generates a UID from the MAC address or whoami output, then beacons to the C2 to receive commands: execute a shell command and return output, check for and upload a file, or receive and save a file to disk. The DNS agent supports the same command execution and file transfer functions. Persistence is achieved via Windows Task Scheduler. To improve delivery odds, OilRig disguised the malware as a legitimate Cisco AnyConnect VPN application, though implementation errors were present — including a popup appearing on every click and a typo rendering one sample non-functional ("Poweeershell.exe"). Other sloppiness included PDB paths left in binaries and tampered compilation timestamps set to future dates. No specific targeted sectors or countries are named in this report.
read more about OilRig's Poison Frog: From PowerShell Backdoors to Cisco AnyConnect Disguises - Public
ZeroCleare Wiper Targets Middle Eastern Energy Sector in Destructive Cyberattack
IBM's X-Force team has detailed a new destructive malware, ZeroCleare, targeting the energy sector in the Middle East. The wiper, similar to Shamoon, overwrites data and maliciously uses legitimate tools. Attribution points to Iranian state-sponsored groups, possibly a collaboration between ITG13 and another entity. The report highlights the increase in destructive attacks, particularly in the energy sector, and offers mitigation strategies, including the use of threat intelligence, robust security controls and effective backup systems. Finally, it notes the wider geopolitical implications of such attacks.
read more about ZeroCleare Wiper Targets Middle Eastern Energy Sector in Destructive Cyberattack - Public
Persistent Exploits in Microsoft Outlook: Iranian Hackers Bypass Security Patches
Iranian APT groups, notably APT34 and APT33, have exploited the CVE-2017-11774 vulnerability in Microsoft Outlook, using it for espionage and destructive attacks. This exploit involves modifying Outlook's homepage settings via the registry to achieve persistence and remote code execution, bypassing Microsoft's patch. The attacks have targeted sectors globally, leveraging custom phishing documents and Azure-hosted payloads to bypass security measures and maintain control over compromised systems.
read more about Persistent Exploits in Microsoft Outlook: Iranian Hackers Bypass Security Patches - Public
Leaked Toolkit Exposes APT34’s Sophisticated Cyberattacks
This NSFOCUS report details an analysis of a leaked toolkit belonging to the APT34 hacking group, also known for its similarities to OilRig. The report focuses on the toolkit's components, including Trojans such as Glimpse and PoisonFrog, and Webshells used for privilege escalation and data exfiltration, primarily targeting the energy and financial sectors, particularly in China and the Middle East. The analysis details the functionality and communication methods of the tools, which use DNS tunneling for command and control.
read more about Leaked Toolkit Exposes APT34’s Sophisticated Cyberattacks - Public
Unraveling PoisonFrog: DNS Tunneling Tactics of OilRig Explored
The IronNet Threat Research team explored PoisonFrog malware, revealing its DNS tunneling capabilities for covert communications. This PowerShell-based malware, linked to the OilRig/APT34 group, abuses DNS protocol to establish command and control channels, avoiding direct malicious infrastructure connections. PoisonFrog crafts DNS queries to register, receive tasks, and transmit data, leveraging recursion for seamless integration into victims' DNS infrastructures. Despite its sophisticated DNS usage, PoisonFrog includes an HTTP fallback for command and control, indicating preparedness for DNS communication failure.
read more about Unraveling PoisonFrog: DNS Tunneling Tactics of OilRig Explored - Public
OilRig's Use of BONDUPDATER: A Stealthy Cyber Espionage Campaign on Bahrain
NETSCOUT ASERT captured live command and control traffic from an updated BONDUPDATER variant targeting the Office of the First Deputy Prime Minister of Bahrain via spearphishing emails — activity the team attributes to OilRig (APT34). ASERT reverse-engineered the malware's C2 protocol in real time, documenting two key mechanisms. Command delivery uses DNS TXT records: the attacker's nameserver returns base64-encoded commands (with modified padding characters) in a structured format prefixed by a 5-character identifier and delimited by a ">" character, allowing multi-part commands to be reassembled on the victim machine. Data exfiltration uses DNS A record queries, with output stuffed into custom subdomains using a distinctive nibble-splitting obfuscation technique: each byte of data is split into its two 4-bit nibbles, with first nibbles placed in one list and second nibbles in another, joined end-to-end to form subdomain strings. Exfiltration sessions are bracketed by "COCTab" (start) and "COCTabCOCT" (end) markers in the subdomain, alongside a command identification value allowing the attacker to map responses to issued commands. ASERT observed the attacker running whoami and ipconfig /all as initial reconnaissance commands. The C2 domain used was withyourface[.]com. NETSCOUT notes that BONDUPDATER's continuous development — including this new obfuscation layer — indicates OilRig's ongoing investment in evading detection, and recommends monitoring DNS traffic for abnormally long domain names and scanning DNS A record subdomains for the "COCTab" string as a specific detection indicator.
read more about OilRig's Use of BONDUPDATER: A Stealthy Cyber Espionage Campaign on Bahrain - Public
Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations
Cyware's August 2019 overview profiles APT34 (also known as Helix Kitten, OilRig, and Greenbug), an Iranian state-sponsored threat group active since 2014. The group targets organizations across the Middle East and beyond, focusing on finance, government, energy, telecommunications, IT, military, healthcare, and education sectors. APT34 is assessed to collect intelligence that serves Iran's economic and geopolitical interests. Over a five-year period, its campaigns evolved from spearphishing Middle Eastern banks with weaponized Excel attachments to broader global operations. Notable campaigns include exploitation of CVE-2017-0199 (OLE remote code execution) against Israeli institutions in April 2017, and CVE-2017-11882 (Office memory corruption) in October 2017 UAE government targeting. The group deployed a large custom malware arsenal including Helminth, OopsIE, POWRUNER, BONDUPDATER, Karkoff, ISMAgent, Poison Frog, Neptun, and web shells (TwoFace, RGDoor, HyperShell, HighShell, RunningBee, PhpSpy). In April 2019, the threat actor "Lab Dookhtegan" publicly leaked APT34 tools and victim lists. In June 2019, Russian group Turla was discovered hijacking APT34 infrastructure to deliver its own Neptun backdoor. A total of 101 C2 IPs, 63 domains, 117 shell URLs, and 9 file hashes are documented as indicators of compromise from this report.
read more about Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations - Public
APT34's Phishing Strategy With New Malware Families Targeting Key Sectors
Mandiant detected a phishing campaign by APT34, an Iranian-nexus threat actor, in late June 2019. The actor, posing as a member of Cambridge University, delivered malicious documents via LinkedIn and introduced three new malware families. The primary industries targeted by this campaign were Energy and Utilities, Government, and Oil and Gas. APT34 is notably active in the Middle East, employing a blend of public and non-public tools to carry out its cyber espionage activities.
read more about APT34's Phishing Strategy With New Malware Families Targeting Key Sectors - Public
A Deep Dive into APT34's Leaked Tool: Analyzing the Jason Project
Marco Ramilli provides an independent technical analysis of the Jason Exchange Mail BF tool (v7.0), leaked by Lab Dookhtegan on June 3, 2019, as part of the APT34 tool exposure on Telegram. Jason is a graphical .NET tool designed to brute-force Microsoft Exchange accounts and harvest email addresses and account credentials. It was distributed in a ZIP container containing three components: Jason.exe (the GUI frontend), Microsoft.Exchange.WebService.dll (version 15.0.0.0, dated to 2012 despite a last-available 2015 release — suggesting the tool may have been initially developed or frozen around that period), and a password pattern library (PassSample folder with Year.txt, numspecial.txt, num4.txt, num4special.txt, and username/password list files). Three attack modes are selectable: EWS (Exchange Web Services), OAB (Offline Address Book), or both simultaneously; a DNS domain discovery function is also present in the code for auto-detecting Exchange servers. The tool supports configurable thread counts for attack speed tuning. Ramilli notes the developer implemented extensive exception-handling protections — checks for null bytes, variable validation, object index and key guards — which he interprets as either targeting non-technical end users or reflecting professionally-trained development practices. He identifies weak code style similarities with other APT34 tools (Glimpse, WebMask) in exception protection patterns and file logging conventions, but explicitly withholds personal attribution, noting these similarities are insufficient for confident APT34 attribution beyond the trusted source (Lab Dookhtegan). The PDB path (D:\Project\Jason\obj\Release\Jason.pdb) and version string "Jason - Exchange Mail BF - v 7.0" confirm the internal project name. Ramilli publishes a YARA rule (_APT34_Jason) with 20 strings for detection. Source URL is no longer accessible; this analysis is based on the archived PDF attachment.
read more about A Deep Dive into APT34's Leaked Tool: Analyzing the Jason Project - Public
Lab Dookhtegan Exposes APT34's Email Hacking Tool: The Silent Threat of 'Jason'
Telsy published the first public analysis of Jason on June 3, 2019 — the same day Lab Dookhtegan released it on Telegram — making this the earliest documented response to the leak. Jason is a .NET graphical tool designed to brute-force Exchange email accounts using OAB and EWS methods, with support for user/password lists loaded from text files and configurable multi-threading. The tool was not flagged by any VirusTotal engine at time of analysis; Telsy explicitly notes this and calls on security vendors to classify Jason and similar hacking tools as potentially malicious. Scan results are written to out-[datetime].txt files; debug and activity logs are saved to log.txt. Telsy characterizes the tool as "simple old-style appearing but potentially very effective" and notes that multiple versions appear to have been released over time, with version 7.0 likely dating to early 2019. On June 4, 2019, Telsy published a tlp:white YARA detection rule for Jason on their public GitHub repository (github.com/telsy-cyberops/research/blob/master/APT34/YARA), available for immediate use by defenders.
read more about Lab Dookhtegan Exposes APT34's Email Hacking Tool: The Silent Threat of 'Jason' - Public
Cyber Espionage Unveiled: APT34's Targeted Attacks on Government and Finance Systems
APT34 primarily targets Middle Eastern countries and international organizations across finance, government, energy, chemical engineering, and telecommunications sectors. Disclosed by Lab Dookhtegan, APT34 employs various attack methods, including SQL injection, brute-force cracking, and 0-day exploits. The group frequently uses web shells injected into compromised systems to maintain control. Top attacked countries include the United Arab Emirates, China, Jordan, and Saudi Arabia. The compromised enterprises predominantly belong to government (36%), finance (17%), service provider (12%), and media (7%) sectors. APT34's attacks typically begin with exploiting web vulnerabilities to gain initial access.
read more about Cyber Espionage Unveiled: APT34's Targeted Attacks on Government and Finance Systems - Public
APT34's Glimpse Project: Sophisticated Cyber Espionage in the Middle East
Since at least 2014, APT34, has targeted financial, government, energy, chemical, telecommunications, and other industries in the Middle East. Their Glimpse project uses a file-based command and control structure, including a VBS launcher and a PowerShell payload, with covert channels over DNS. Tools leaked on a Telegram channel were linked to OilRig, confirming their use in multiple intrusions across the Middle East and Asia. The attacks include sophisticated PowerShell scripts for command execution and data exfiltration.
read more about APT34's Glimpse Project: Sophisticated Cyber Espionage in the Middle East - Public
OilRig's Global Cyber Offensive: Credential Theft and Persistent Access
The OilRig group has been actively targeting various sectors, including government, media, energy, and technology across 27 countries. The group has stolen nearly 13,000 credentials, deployed over 100 webshells, and maintained backdoor access to compromised hosts. Techniques include credential dumping with Mimikatz, DNS hijacking, and using PowerShell-based tools like Glimpse and Poison Frog. Their operations involve SQL injections, exploiting public-facing applications, and leveraging webshells for persistent access. The group's sophisticated TTPs underline their persistent threat to diverse industry verticals.
read more about OilRig's Global Cyber Offensive: Credential Theft and Persistent Access - Public
APT34’s Webmask Project: DNS Hijacking and Targeted Cyber Attacks
APT34 has been leveraging DNS tunneling for command and control since May 2016. The leaked source code, revealed via a Telegram channel, includes projects like webmask which primarily focus on DNS hijacking and redirection attacks. The attacks target sectors such as technology firms, telecom companies, and gaming companies across the Middle East and Asia, with a particular focus on UAE. The setup involves using NodeJS and Python for DNS servers, an ICAP proxy server to intercept and modify connections, and Haproxy for high availability.
read more about APT34’s Webmask Project: DNS Hijacking and Targeted Cyber Attacks - Public
APT34 Leak Exposes Espionage Tools and Tactics of Iranian Cyber Actors
The APT34/OILRIG group, linked to Iranian intelligence, had its operational details leaked by the "Lab Dookhtegan" group on Telegram. The leaks revealed a C2 infrastructure, PowerShell-based agents, ASP web shells ("HighShell" and "HyperShell"), and a DNS-based espionage toolset ("dnspionage"). These tools facilitate file transfer, credential theft and covert communication via proxies and DNS manipulation. The attackers also collected sensitive data, including domain admin credentials, indicating a potential target for high-value networks. While specific sectors or countries are not detailed, the tools suggest a focus on espionage and disruption. Other tools, such as 'MinionProject' and 'FoxPanel222', remain under analysis.
read more about APT34 Leak Exposes Espionage Tools and Tactics of Iranian Cyber Actors - Public
Analyzing OilRig's Use of DNS Tunneling in Cyber Espionage Campaigns
The report highlights OilRig’s deployment of tools like Helminth, ISMAgent, ALMACommunicator, BONDUPDATER, and QUADAGENT, which utilize DNS queries to communicate stealthily with C2 servers. This covert communication method is favored due to DNS's typical allowance through security devices. The group has evolved its DNS tunneling protocols over time, using customized subdomains and encoding techniques to transmit data and evade detection effectively.
read more about Analyzing OilRig's Use of DNS Tunneling in Cyber Espionage Campaigns - Public
HELIX KITTEN: Expanding Cyber Threat to Telecommunications and Middle Eastern Targets
The adversary group, HELIX KITTEN, is employing spear-phishing attacks and using custom PowerShell implants (Helminth and ISMDoor) to target entities in the aerospace, energy, financial, government, hospitality, and telecommunications sectors. With a special focus on the Middle East, specifically Bahrain and Kuwait, the group manipulates DNS AAAA records for command and control, and exfiltrates data, captures screenshots, and executes arbitrary commands on victims' machines. Furthermore, HELIX KITTEN has begun targeting the telecommunications industry, possibly for bulk data collection and rerouting communications for future intelligence activities.
read more about HELIX KITTEN: Expanding Cyber Threat to Telecommunications and Middle Eastern Targets - Public
Uncovering OilRig’s Malware Testing Ops for Targeted Attacks in the Middle East
Palo Alto Unit42 provides unique insight into OilRig's pre-attack operational tempo by reconstructing a 6-day testing timeline that preceded the August 26, 2018 BONDUPDATER attack on a Middle Eastern government. By analyzing 11 test Excel documents submitted to public VirusTotal-style scanning services between August 20–26, Unit42 mapped every iterative macro change the attacker made to lower AV detection rates — from 22 detections on the first submission down to 7 on the last, with a rebound to 38 on the final weaponized Word document (N56.15.doc). The test files were named XLS-withyourface.xls and sss.xls, with the C2 domain (withyourface[.]com) embedded directly in the early filenames, linking them conclusively to the BONDUPDATER attack. The tester averaged 33 seconds between file save and VirusTotal submission, conducted three testing waves, and pivoted from Excel to Word for the final delivery document. Key technical lessons the attacker applied: removing the "powershell.exe" string from VBScript lowered detections from 22 to 16; removing the wscript execution call dropped detections from 16 to 6; using vbHide (hidden window) flag caused 8 additional detections compared to vbNormalFocus (visible window); and hex-character concatenation obfuscation of "powershell", "cmd.exe", and "wscript" strings bypassed most detections. The final weaponized Word document was created less than 8 hours after the last test iteration and delivered via spearphishing 20 minutes after its creation, setting a precise operational tempo. OilRig also added a 10-second sleep using Application.Wait during some testing iterations as an anti-sandbox technique, though this was removed in the final payload.
read more about Uncovering OilRig’s Malware Testing Ops for Targeted Attacks in the Middle East