Threats Feed
- Public
The Shadow of Rocket Kitten: Exploring a Sophisticated VMware Exploit
Morphisec identified exploitation of a VMware Workspace ONE Access vulnerability, believed to be the work of an APT group, likely the Iranian-linked Rocket Kitten. The attack involved server-side template injection and execution of PowerShell commands via the Tomcat prunsrv.exe process application, leading to full remote code execution. The attackers deployed a PowerShell stager that downloaded the PowerTrash Loader. The end payload was a Core Impact Agent. The tactics are known to enable ransomware or coin miners deployment, evading typical defenses like antivirus and endpoint detection and response.
read more about The Shadow of Rocket Kitten: Exploring a Sophisticated VMware Exploit - Public
Iran-Based TG-2889 Uses Fake LinkedIn Network to Target Middle East Telecom and Defense
In October 2015, Dell SecureWorks Counter Threat Unit (CTU) researchers uncovered a network of 25 fake LinkedIn profiles created by TG-2889, a suspected Iran-based threat group linked to Operation CLEAVER. The fake accounts were divided into two tiers: eight "Leader" personas with detailed professional histories, 500+ connections, and skills endorsements — purporting to work for companies including Teledyne Technologies, Northrop Grumman, Doosan, and Petrochemical Industries Co. — and 17 simpler "Supporter" personas designed solely to endorse the Leader accounts and artificially boost their credibility. Five Leader personas posed as recruitment consultants, providing a natural pretext to approach targets with job offers. CTU researchers identified 204 likely victims based on users who had endorsed the fake Leader profiles; a quarter worked in telecommunications (Middle Eastern and North African mobile operators featured heavily), with significant minorities in Middle Eastern governments and defense organizations. The threat actors also demonstrated a novel technique — replacing one persona's identity with another on the same LinkedIn account, inheriting the accumulated network and endorsements while refreshing the cover identity. Fake domains matching the impersonated companies (teledyne-jobs[.]com, doosan-job[.]com, northropgrumman[.]net) link TG-2889 to the Operation CLEAVER malware campaign documented by Cylance, which used fake job application portals to deliver malware. The group's geographic focus on Arab states in the MENA region is consistent with Iran-based threat actor targeting.
read more about Iran-Based TG-2889 Uses Fake LinkedIn Network to Target Middle East Telecom and Defense - Public
Thamar Reservoir: Iranian Cyber Campaign Targets Middle East Sectors
Clearsky's "Thamar Reservoir" report details a sustained Iranian cyber-attack campaign targeting over 550 individuals, primarily in the Middle East. The attacks, which began in 2014, used a variety of techniques, including spear-phishing emails with malware, phone calls, and compromised websites to create fake login pages. The attackers were persistent but lacked technical sophistication and made mistakes that aided the investigation. The report concludes that the campaign's targets and methods strongly suggest Iranian state sponsorship, and links it to other known Iranian cyber operations.
read more about Thamar Reservoir: Iranian Cyber Campaign Targets Middle East Sectors - Public
Rocket Kitten’s Operation Woolen-GoldFish Targets Israeli and European Organizations
This Trend Micro report details the activities of Rocket Kitten, a cyber threat group targeting Israeli and European organisations. The report focuses on two campaigns: a malware campaign using the GHOLE malware, possibly dating back to 2011, and a suspected state-sponsored operation, 'Operation Woolen-GoldFish', involving spear-phishing attacks. Analysis shows possible links to an individual using the alias "Wool3n.H4t", possibly Iranian, and highlights the group's increasing sophistication despite using relatively simple techniques such as macros. The overall aim is to inform readers of Rocket Kitten's methods and suspected politically motivated objectives, suggesting Iranian involvement.
read more about Rocket Kitten’s Operation Woolen-GoldFish Targets Israeli and European Organizations