Threats Feed
- Public
Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.
read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors - Public
UNC1549’s Advanced Espionage Campaign Against the Aerospace and Defense Ecosystem
UNC1549, a suspected Iran-nexus threat group, has conducted sustained cyber espionage campaigns since mid-2024 targeting the aerospace, aviation, and defense sectors across the Middle East and connected partner ecosystems. The group gained initial access through targeted spear-phishing and exploitation of trusted third-party relationships, including breakouts from Citrix and VMWare VDI environments. Once inside, UNC1549 deployed custom malware families such as MINIBIKE, TWOSTROKE, DEEPROOT, LIGHTRAIL, and POLLBLEND, heavily relying on DLL search order hijacking, reverse SSH tunnels, and Azure-based C2. Their operations focused on long-term persistence, credential theft (including DCSync attacks), stealthy lateral movement, and extensive data collection from high-value defense networks.
read more about UNC1549’s Advanced Espionage Campaign Against the Aerospace and Defense Ecosystem - Public
Global Financial Executives Hit by Multi-Stage Phishing Operation
A sophisticated spear-phishing campaign targeted CFOs and finance executives in banking, energy, insurance, and investment sectors across the UK, Canada, South Africa, Norway, South Korea, Singapore, Switzerland, France, Egypt, Saudi Arabia, and Brazil. Disguised as a Rothschild & Co recruiter, the attackers used Firebase-hosted phishing pages protected by custom CAPTCHAs to deliver multi-stage payloads. Victims who executed malicious VBS scripts unknowingly installed NetBird and OpenSSH, granting attackers persistent, encrypted remote access through hidden admin accounts and RDP activation. Trellix researchers identified infrastructure overlaps with previous nation-state campaigns but withheld attribution.
read more about Global Financial Executives Hit by Multi-Stage Phishing Operation - Public
Fake Assassination News Used in Phishing Attack Impersonating The New York Times
A phishing campaign is exploiting sensational fake news about an assassination attempt on US President-elect Donald Trump by an Iranian sniper. The campaign poses as The New York Times using the email address newyork-times@nycmail[.]com. Victims who click on the embedded link are redirected to an ESET-imitation phishing site, where they are prompted to enter corporate domain credentials. This campaign is an example of attackers using major global events, such as political elections, to amplify their efforts. The use of urgency and sensational headlines highlights the need for vigilance in verifying information.
read more about Fake Assassination News Used in Phishing Attack Impersonating The New York Times - Public
Brute Force and MFA Push Bombing Tactics Used in Iranian Cyber Campaign
Iranian cyber actors targeted critical infrastructure sectors in the US, Canada, and Australia, including healthcare, government, energy, and IT organisations. The attackers used password spraying and MFA push bombing to obtain valid accounts and access systems such as Microsoft 365, Azure, and Citrix. They used open source tools to gain access to credentials, including Kerberos SPN enumeration and Active Directory dumps. In some cases, the attackers attempted to exploit the Netlogon vulnerability for privilege escalation. In addition, the actors used discovery techniques using living-off-the-land tools to identify domain controllers, trusted domains and administrative accounts.
read more about Brute Force and MFA Push Bombing Tactics Used in Iranian Cyber Campaign - Public
Malware Masquerading as Palo Alto GlobalProtect Targets Middle Eastern Organizations
Threat actors are targeting users in the Middle East with malware disguised as the Palo Alto GlobalProtect VPN tool. Delivered likely through phishing, the malware employs a two-stage infection chain initiated via a malicious setup.exe. It uses advanced command-and-control (C2) infrastructure, including newly registered domains like “sharjahconnect” and the Interactsh project for beaconing. Written in C#, the malware supports remote PowerShell execution, file download/exfiltration, and AES-encrypted communications. It also features sandbox evasion, system information gathering, and beaconing mechanisms to track infection stages. This campaign highlights significant threats to organizations in the region, particularly those reliant on VPN-based remote access.
read more about Malware Masquerading as Palo Alto GlobalProtect Targets Middle Eastern Organizations - Public
State-Sponsored Cyberattacks Target Israeli Academia and Government Sectors
Recent cyberattacks by state-sponsored groups have targeted Israeli organizations in academia, local government, and managed service providers (MSPs). These attacks aim to cause substantial damage by erasing critical data from servers and workstations using Microsoft's SDelete tool from the SYSInternals suite. The attackers leverage outdated VPN servers to gain initial access, followed by lateral movements within networks to reach their targets. Several organizations have already been impacted, predominantly through an attack on the supply chain, hindering data restoration efforts.
read more about State-Sponsored Cyberattacks Target Israeli Academia and Government Sectors - Public
Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation
In December, an Iranian attack group launched a phishing campaign impersonating F5 company to target Israeli economic sectors. The campaign aimed for destructive attacks and information gathering. It involved emails from a spoofed F5 address, containing links to download Wiper and Infostealer malware. The attack exploited an F5 critical warning, requiring users to run a Shell Script file. Malicious files included a .NET-based f5updater.exe for Windows and a Bash Script for Linux. These scripts, effective only with administrative privileges, were designed for data destruction and information stealing, with the latter employing advanced evasion techniques like AV service disabling and script obfuscation.
read more about Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation - Public
Iranian-Backed Polonium Group Targets Israeli Critical Infrastructure
The Polonium attack group, associated with the Lebanese faction and the Iranian Ministry of Intelligence, is actively targeting sectors in Israel, namely water, energy, and IT. This group's primary focus is on cyber espionage (CNE), with a recent shift towards potentially destructive activities (CNA). Their strategy involves exploiting known vulnerabilities (N-Day) and leveraging public VPN and cloud services, particularly PCloud, for communication and control. Despite these efforts, significant breaches in Israeli systems have not been confirmed. An alert highlights the risk of exploiting vulnerabilities in Fortinet equipment, underlining the need for enhanced cyber defense measures in the targeted sectors.
read more about Iranian-Backed Polonium Group Targets Israeli Critical Infrastructure - Public
Iranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Cyber National Mission Force (CNMF) identified multiple APT actors exploiting vulnerabilities in an Aeronautical Sector organization as early as January 2023. The actors targeted a public-facing application (Zoho ManageEngine ServiceDesk Plus) and the organization’s firewall device, exploiting CVE-2022-47966 and CVE-2022-42475. They gained unauthorized access, established persistence, moved laterally, and engaged in defense evasion by deleting logs. Although the attackers achieved extensive network enumeration and credential access, the report didn't confirm any data exfiltration.
read more about Iranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack - Public
WINTAPIX: New Kernel Driver Targets Middle Eastern Countries
Fortinet researchers discovered WINTAPIX, a sophisticated Windows kernel driver suspected to be the work of Iranian threat actors, targeting IIS web servers across the Middle East — primarily in Saudi Arabia, with additional targeting of Jordan, Qatar, and the United Arab Emirates. Active since at least mid-2020, the malware remained largely undetected for years before significant spikes in activity emerged in August–September 2022 and February–March 2023. WINTAPIX operates at the kernel level, giving it deep system access and making it significantly harder to detect and remove than user-mode implants. The driver uses the open-source Donut framework to generate and inject shellcode that loads an obfuscated .NET payload into a target process. The payload — protected with SmartAssembly and Eazfuscator to resist reverse engineering — provides the operators with backdoor access and proxy functionality, enabling persistent remote control and traffic tunneling through the compromised IIS server. The driver itself is shielded with VMProtect, transforming its code into a virtualized format to hinder static analysis.
read more about WINTAPIX: New Kernel Driver Targets Middle Eastern Countries - Public
TA452 Utilizes PowerShell and AutoHotkey in its Intrusion
TA452's August 2022 intrusion involved a malicious Word document with a VBA macro that established persistence and C2 communication. The threat actors used AutoHotkey for keylogging, PowerShell scripts for discovery, and exfiltrated data using makecab.exe. They employed sophisticated techniques such as base64 encoding, obfuscation, and scheduled tasks to maintain access and evade detection. The campaign is linked to OilRig group and targeted organizations with custom-tailored malware, hinting at state-sponsored activity. Data was exfiltrated over encrypted channels, with evidence pointing to an organized and targeted approach.
read more about TA452 Utilizes PowerShell and AutoHotkey in its Intrusion - Public
Iranian APTs Exploit Log4Shell to Compromise FCEB Network
In April 2022, CISA detected Iranian government-sponsored APT activity compromising an FCEB organization's network via the Log4Shell vulnerability. Initial exploitation targeted an unpatched VMware Horizon server, later spreading to the domain controller. The threat actors utilized PowerShell commands, disabled Windows Defender, and established persistence through scheduled tasks. Tools like Mimikatz and Ngrok were deployed for credential harvesting and C2 communication. Despite attempts to dump the LSASS process, additional anti-virus measures thwarted this activity. Lateral movement was observed, as were activities aimed at credential and account manipulation.
read more about Iranian APTs Exploit Log4Shell to Compromise FCEB Network - Public
Iranian State-Sponsored Actors Exploit Log4Shell to Target US Government
In April 2022, Iranian government-sponsored actors exploited the Log4Shell vulnerability in VMware Horizon servers, targeting a Federal Civilian Executive Branch (FCEB) organization. They installed XMRig crypto mining malware and used tools like Mimikatz and Ngrok for credential theft and tunneling. The attack involved disabling Windows Defender, downloading malicious files, hiding artifacts, and creating scheduled tasks for persistence. The campaign highlights advanced tactics in disabling security controls and maintaining persistent access. The targeted sector was the US government.
read more about Iranian State-Sponsored Actors Exploit Log4Shell to Target US Government - Public
Sophisticated PowerShell Attack Targets Systems with Spearphishing
The Fully Undetectable (FUD) PowerShell backdoor report details a sophisticated attack beginning with a malicious Word document ("Apply Form.docm") used in a LinkedIn-based spearphishing campaign originating from Jordan. The document contains a macro that launches a PowerShell script, creating a scheduled task to execute further malicious actions. The backdoor communicates with its C2 server, executing various commands such as process list exfiltration, user enumeration, and Active Directory exploration. SafeBreach identified operational security mistakes allowing decryption of the C2 commands. The campaign, involving PowerShell scripts and scheduled tasks, targets systems for data exfiltration and potential lateral movement.
read more about Sophisticated PowerShell Attack Targets Systems with Spearphishing - Public
POLONIUM Cyber Espionage: Focused Attacks on Israeli Organizations Across Multiple Sectors
The POLONIUM group has been actively targeting more than a dozen organizations in Israel since September 2021, with a focus on various sectors including engineering, IT, law, communications, branding and marketing, media, insurance, and social services. The group's arsenal comprises several custom backdoors like CreepyDrive, CreepySnail, DeepCreep, MegaCreep, FlipCreep, TechnoCreep, and PapaCreep, along with other spying modules. These backdoors utilize cloud services like OneDrive, Dropbox, and Mega for command and control operations and are involved in collecting confidential data without engaging in sabotage or ransomware activities. The initial access to targeted systems might have been gained through the abuse of leaked VPN credentials.
read more about POLONIUM Cyber Espionage: Focused Attacks on Israeli Organizations Across Multiple Sectors - Public
Iranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns
Iranian Islamic Revolutionary Guard Corps-affiliated cyber actors exploited vulnerabilities in Fortinet FortiOS, Microsoft Exchange, and VMware Horizon applications since early 2021, targeting entities in the U.S., U.K., and Australia. These vulnerabilities, including CVE-2018-13379, CVE-2020-12812, CVE-2019-5591, and several ProxyShell issues, were used for initial access, ransom operations, and data exfiltration. Activities include encrypting data for ransom, extortion operations, and crypto-mining, impacting sectors like law enforcement, transportation, municipal government, and aerospace. The actors leveraged tools like FRP, Plink, RDP, and BitLocker for command and control, lateral movement, and encryption.
read more about Iranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns - Public
CodeRAT Targets Farsi-Speaking Developers with Innovative C2 Techniques
SafeBreach Labs has discovered CodeRAT, a new remote access trojan (RAT) targeting Farsi-speaking software developers with capabilities ranging from espionage to data exfiltration. Delivered via a Word document that exploits Microsoft DDE, CodeRAT monitors activity in various applications, particularly those related to social networking and development tools. Uniquely, it uses public file upload APIs and Telegram groups for command and control, bypassing typical C2 infrastructure. The malware supports 50 commands, including clipboard capture, process control and file upload. The CodeRAT developer released the source code on GitHub after it was discovered by researchers.
read more about CodeRAT Targets Farsi-Speaking Developers with Innovative C2 Techniques - Public
UNC3890: The Iranian Nexus Behind Attacks on Israeli Shipping and Healthcare
Mandiant's August 2022 report introduces UNC3890, a suspected Iranian-nexus threat actor tracked since late 2020, targeting Israeli shipping, government, energy, aviation, and healthcare organizations. Attribution indicators include Farsi language artifacts in malware code ("KHODA" meaning god, "yaal" meaning horse's mane), focused targeting of Israeli entities consistent with other Iranian actors, and a shared PDB path with UNC2448 (an IRGC-linked group). UNC3890 employs two custom tools: SUGARUSH — a small TCP reverse-shell backdoor that creates a "Service1" Windows service, connects to a hardcoded C2 on port 4585, and executes received CMD commands — and SUGARDUMP, a Chromium browser credential harvester with three observed versions: an early version (stores credentials locally), an SMTP version (exfiltrates via Yahoo/Yandex/Gmail using john.macperson2021 accounts, uses a robotic dolls commercial as lure), and an HTTP version (AES-CBC encrypted exfiltration to C2, uses a fake LexisNexis job offer lure). Initial access vectors include a watering hole on a legitimate Israeli shipping company's login page (sending victim data to xn--lirkedin-vkb[.]com), credential harvesting via lookalike domains (pfizerpoll[.]com, office365update[.]live, rnfacebook[.]com), spearphishing links, and potentially trusted relationships. Public tools used include Metasploit, UNICORN (Magic Unicorn), and NorthStar C2. IOCs include 8 C2 IPs, 10 domains (including a Punycode LinkedIn lookalike), 4 attacker email addresses, and 23 file hashes.
read more about UNC3890: The Iranian Nexus Behind Attacks on Israeli Shipping and Healthcare - Public
Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing
In early January 2021, Proofpoint researchers identified the Iran-aligned APT actor TA451 (also known as APT33) running a spearphishing campaign against a US defense contractor using COVID-19-themed lures. The actor masqueraded as the World Health Organization, delivering emails with a link to a malicious executable named COVID19tracker[.]exe. Once a user executed the file, it reached out to download a batch script (iehchecker[.]bat), which in turn retrieved a PowerShell script (Update-KB4524147[.]ps1) with reverse shell capabilities, giving the attacker remote access to the compromised host. The campaign is documented as a case study in TA451's social engineering tradecraft within Proofpoint's broader 2022 Social Engineering Report, which covers threat actor tactics observed throughout 2021 — including multi-stage infection chains, impersonation of trusted organizations, and exploitation of topical events to lower victim defenses.
read more about Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing - Public
Iranian-Linked POLONIUM Targets Israeli Manufacturing and Defense Industries
POLONIUM, suspected to be coordinating with Iran's Ministry of Intelligence and Security, is actively targeting Israeli organizations across multiple sectors such as critical manufacturing, IT, and defense. The group exploits supply chain vulnerabilities by compromising IT companies to further target downstream organizations like aviation companies and law firms. TTPs include custom implants like CreepyDrive that use cloud services for C2 and data exfiltration. MSTIC also notes overlap with Iranian groups MERCURY, CopyKittens, both in targeted victims and techniques like using AirVPN and OneDrive. Though unconfirmed, around 80% of victims were observed running Fortinet appliances, suggesting a potential CVE-2018-13379 exploitation.
read more about Iranian-Linked POLONIUM Targets Israeli Manufacturing and Defense Industries - Public
ENT-11: Iranian APT Group's PowGoop Attacks Uncovered
The Iranian APT group ENT-11, also known as MuddyWater, has been using a variant of the PowGoop malware, dubbed "E400", targeting foreign governments, telecommunications, energy sectors, intergovernmental economic cooperation organizations, and the banking sector, primarily in the Middle East. Insights from NTT Security revealed dozens of PowGoop command and control servers dating back to October 2020. The group appears to be winding down operations with the E400-PowGoop variant, but it is expected to continue modifying its tools and creating new variants.
read more about ENT-11: Iranian APT Group's PowGoop Attacks Uncovered - Public
Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers
SafeBreach Labs discovered an Iranian threat actor exploiting the MSHTML vulnerability (CVE-2021-40444) to infect Farsi-speaking victims with the PowerShortShell stealer via spear phishing. The attack, first reported in September 2021, involved a malicious Word document connecting to a server, downloading a DLL, and executing a PowerShell script. This script collected data, including screenshots and files, and exfiltrated it to the attacker's server. The campaign targeted Iranians abroad, particularly in the United States, suggesting ties to Iran's Islamic regime.
read more about Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers - Public
Iranian APT Group Exploits Microsoft and Fortinet Vulnerabilities: A Broad Spectrum Cyber Assault
Some Iranian government-sponsored APT groups have exploited vulnerabilities in Microsoft Exchange servers and Fortinet devices since March 2021. These actors broadly targeted critical infrastructure sectors in the US, including Transportation and Healthcare and Public Health, as well as Australian organizations. The APT group focused more on exploiting known vulnerabilities rather than specific sectors, using the gained access for ransomware deployment, data exfiltration, and extortion. Several tactics, techniques, and tools were utilized, including creating new user accounts and modifying Task Scheduler.
read more about Iranian APT Group Exploits Microsoft and Fortinet Vulnerabilities: A Broad Spectrum Cyber Assault