Threats Feed
- Public
Tortoiseshell's Cross-Platform Espionage Targets Military and Defense Industries in US, UK, and Europe
Tortoiseshell targeted military personnel and companies in the defense and aerospace industries, primarily in the United States and, to a lesser extent, the UK and Europe. The group used social engineering, phishing, and custom malware tools, including Syskit and a Liderc-like reconnaissance tool, to compromise and profile victims' systems. The campaign involved fake online personas, spoofed domains, and outsourced malware development to Tehran-based IT company Mahak Rayan Afraz (MRA), which has ties to the Islamic Revolutionary Guard Corps (IRGC).
read more about Tortoiseshell's Cross-Platform Espionage Targets Military and Defense Industries in US, UK, and Europe - Public
SpoofedScholars: TA453 Targets Intelligence Interests Posing as British Scholars
Iranian-state aligned actor TA453 has been covertly targeting individuals of intelligence interest to the Iranian government by masquerading as British scholars from the University of London's School of Oriental and African Studies (SOAS). The threat actor, targeted Middle Eastern experts, senior professors, and journalists. TA453 compromised a legitimate academic website to deliver personalized credential harvesting pages.
read more about SpoofedScholars: TA453 Targets Intelligence Interests Posing as British Scholars - Public
Ferocious Kitten APT Targets Iranian Users with Sophisticated MarkiRAT Malware
Ferocious Kitten, an APT group active since 2015, primarily targets Persian-speaking individuals in Iran using weaponized documents. The attack involves malicious macros in documents, such as “Romantic Solidarity With Lovers of Freedom2.doc”, to drop executables that display anti-regime messages. These executables, once enabled, ensure persistence by placing themselves in the startup directory. The group's malware, MarkiRAT, exhibits capabilities like process checking, logging keystrokes, hijacking Telegram installations, and communicating with a C2 server. It specifically targets security solutions like Kaspersky and Bitdefender, indicating a high level of sophistication and focus on evading detection.
read more about Ferocious Kitten APT Targets Iranian Users with Sophisticated MarkiRAT Malware - Public
Agrius: From Espionage to Destructive Cyber Attacks in the Middle East
The Agrius threat actor evolved from conducting espionage to destructive attacks, notably using wipers disguised as ransomware. Initially engaging in data destruction under the guise of encryption for ransom, Agrius later developed fully functional ransomware, targeting primarily Israel and the UAE's critical facilities. Utilizing VPNs for anonymity, Agrius exploited public-facing applications, deploying webshells for initial access, and custom .NET malware, 'IPsec Helper', for persistence and data exfiltration. Their toolkit includes the .NET-based 'Apostle' wiper-turned-ransomware and the DEADWOOD wiper, indicating a sophisticated approach to cyber sabotage and espionage.
read more about Agrius: From Espionage to Destructive Cyber Attacks in the Middle East - Public
Stealthy APT35 Activity in EMEA Corporate Environment
APT35, also known as Charming Kitten, had infiltrated an organization in the EMEA region. The infected corporate device was only engaged in command and control (C2) beaconing and showed no signs of lateral movement or data exfiltration. Despite a mature security stack, the organization was unaware of the infection until the new security measures were implemented.
read more about Stealthy APT35 Activity in EMEA Corporate Environment - Public
Iranian APT34's Evolving Arsenal: A Deep Dive into the SideTwist Campaign
The article from Check Point Research focuses on the resurgence of Iran's APT34 cyber espionage group, which has updated its tactics and tools. This group, also known as OilRig, has targeted a Lebanese entity using a new backdoor variant named "SideTwist". They have refined their strategies to evade detection, continuing their pattern of using job opportunity documents to deliver malware through LinkedIn. The article provides an in-depth analysis of the infection chain, the malware's capabilities, and its persistence techniques. It aligns with APT34's history of targeting Middle Eastern entities, underscoring the ongoing cyber threats in the region.
read more about Iranian APT34's Evolving Arsenal: A Deep Dive into the SideTwist Campaign - Public
BadBlood Campaign: TA453 Targets US and Israeli Medical Research Professionals
In late 2020, the Iranian-nexus threat actor TA453 launched a credential phishing campaign called BadBlood, targeting senior medical professionals in genetic, neurology, and oncology research in the United States and Israel. The campaign deviates from the group's usual activity and may indicate a shift in TA453's targeting priorities. The attackers used spearphishing emails with links to a fake OneDrive site to harvest user credentials, potentially to exfiltrate email contents or use compromised accounts for further phishing campaigns.
read more about BadBlood Campaign: TA453 Targets US and Israeli Medical Research Professionals - Public
Automated Scripts Used in Microsoft Exchange ProxyShell Attack By PHOSPHORUS
In December 2021, PHOSPHORUS exploited the Microsoft Exchange ProxyShell vulnerabilities, using web shells to gain initial access and execute code. The attack closely resembled their previous attacks and due to previous reports and OSINT research, DFIR believes with medium to high confidence that this intrusion would have ended in ransomware. The attackers established persistence through scheduled tasks and a newly created account, and after enumerating the environment, disabled LSA protection and dumped LSASS process memory. The entire attack was likely scripted out, as evidenced by the user agent strings and the similarity between commands.
read more about Automated Scripts Used in Microsoft Exchange ProxyShell Attack By PHOSPHORUS - Public
MuddyWater Expands Its Reach: A Deep Dive into the Earth Vetala Intrusion
The MuddyWater threat group, through an intrusion set named Earth Vetala, targeted various organizations in Azerbaijan, Bahrain, Israel, Saudi Arabia, and the United Arab Emirates. The group used spear-phishing emails to distribute malicious packages, predominantly aiming at Government Agencies, Academia, and the Tourism sector. MuddyWater deployed post-exploitation tools to dump passwords and establish a persistent presence within targeted systems. They used multiple C&C servers to execute obfuscated PowerShell scripts and were persistent in attempting multiple techniques to establish connectivity despite repeated failures.
read more about MuddyWater Expands Its Reach: A Deep Dive into the Earth Vetala Intrusion - Public
Decade-Old Foudre APT Adopts “Tonnerre” for Sophisticated Cyber Espionage Activities
Bitdefender researchers uncovered ongoing activities of the Iranian Foudre APT, utilizing a new component, “Tonnerre,” targeting government and private sector entities. The Foudre malware, first identified in 2016, employs a backdoor that compromises Windows systems via a malicious document and binary, ensuring persistence and enabling data exfiltration. Enhanced tactics include improved C&C communication and resilience against forensic investigations. Tonnerre can record audio, capture screenshots, and collect files, transmitting this data to a controlled C&C. The investigation also revealed similarities with previous versions of Foudre and connections to other known malware variants like Infy M.
read more about Decade-Old Foudre APT Adopts “Tonnerre” for Sophisticated Cyber Espionage Activities - Public
Static Kitten Launches Cyberespionage Attack on UAE and Kuwait Government Sectors
The cyberespionage group, Static Kitten, launched a cyber attack primarily targeting the government sectors of the United Arab Emirates (UAE) and Kuwait. Using geopolitical lures and masquerading as the Ministry of Foreign Affairs (MOFA) of Kuwait, the attackers aimed to install a remote management tool called ScreenConnect on victims' devices. The campaign involved phishing emails, URL masquerading, and delivering ZIP files that purport to contain relevant documents but instead initiate the ScreenConnect installation process.
read more about Static Kitten Launches Cyberespionage Attack on UAE and Kuwait Government Sectors - Public
Domestic Kitten: Inside Iran's Surveillance Campaign Against Citizens
APT-C-50's Domestic Kitten surveillance operation, linked to the Iranian government, targets over 1,200 Iranian citizens including dissidents, opposition forces, and minorities. Since 2017, ten campaigns delivered the FurBall malware via Iranian blogs, Telegram channels, and SMS links. FurBall collects device data, call logs, SMS messages, and media files, tracking victims' activities. It leverages commercially available parental control software, KidLogger, for its operations. This extensive surveillance continues with four active campaigns as of November 2020.
read more about Domestic Kitten: Inside Iran's Surveillance Campaign Against Citizens - Public
The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities
The Infy APT evolved its malware Foudre and introduced Tonnerre, targeting US and Israeli entities, including government and veteran affairs. Active since 2007, recent versions (2020) of Foudre changed tactics, using macros in documents to trigger malware, replacing earlier link-based methods. These documents, disguised as legitimate communications (e.g., featuring Iranian officials or organizations), download and execute payloads when closed. Foudre's enhancements include a sophisticated domain generation algorithm and RSA verification to evade detection and secure C2 communication. Tonnerre, a second-stage payload, offers advanced capabilities like file theft, command execution, screen capture, and audio recording. It employs DGA and RSA validation for C2, communicating over HTTP and FTP, and disguises itself as legitimate software to remain undetected.
read more about The Evolution of Infy: Cyber Espionage Campaigns Against Western Entities - Public
Unwrapping Charming Kitten's Holiday Phishing Campaign
During the 2021 Christmas holidays, Iranian state-backed hackers Charming Kitten initiated a targeted phishing campaign against individuals, focusing on personal and business emails. The group used public-facing applications, such as Google services, to redirect victims through a chain of legitimate services, helping bypass security layers in email services and obfuscate their operations. They employed various fake domains and developed custom phishing pages to target a range of online services, collecting sensitive data and emails from victims.
read more about Unwrapping Charming Kitten's Holiday Phishing Campaign - Public
MuddyWater APT Group Linked to Steganography-Based Malware Attack
A new malware strain, potentially linked to the MuddyWater APT group, uses Word files with macros to deploy PowerShell scripts from GitHub, which then download an image from Imgur. The image's pixel values decode a Cobalt Strike payload. This method, involving steganography, enables attackers to execute commands and establish remote control over Windows systems. The attack primarily targets Middle Eastern entities, using phishing emails to distribute malicious Word documents.
read more about MuddyWater APT Group Linked to Steganography-Based Malware Attack - Public
Iranian APT39 Uses Android Malware for Domestic Surveillance
The ReversingLabs analysis, based on an FBI report, reveals that the Iranian-backed APT39 (Rana Corp) is using Android malware for state-sponsored surveillance, primarily targeting individuals deemed a threat by the Iranian government. The malware exploits smartphone features such as the camera and microphone to spy on users. It can intercept SMS, record audio, take photos and manipulate network connections. Obfuscation techniques were used, but analysis of an older sample revealed key capabilities for remote monitoring and control. The malware specifically monitors Iranian messaging apps, suggesting domestic surveillance. Targeted sectors include political dissidents and individuals of interest within Iran.
read more about Iranian APT39 Uses Android Malware for Domestic Surveillance - Public
Pay2Key Ransomware Attack: Companies in Europe and Israel at Risk
Swascan's Cyber Security Research Team conducted first-hand incident response on Pay2Key attacks targeting European companies alongside the simultaneous Israeli campaign documented by Check Point Research. Swascan was one of the first teams to identify the ransomware, submitting Cobalt.Client.exe to VirusTotal on October 27, 2020 — the same day as the first confirmed attacks. Forensic investigation revealed that initial access occurred as early as October 20, 2020, with attackers entering via an exposed vulnerable service and using RDP to connect to compromised devices. From there, PsExec (PSEXESVC.exe) was used to distribute the ransomware across the network. Swascan also identified Ngrok, hidden as dllhost.exe in Windows event logs, as a likely backdoor tool the attackers used to maintain persistent remote access to infected infrastructure. ConnectPC.exe was recovered from crash logs and confirmed as the internal proxy used to relay C2 communications. Ransom demands ranged from $100,000 to $200,000 in Bitcoin depending on company size and the number of compromised devices — a higher ceiling than reported by Check Point. Full-network encryption completed in approximately three hours, with the active encryption phase taking roughly one hour. Only two antivirus engines flagged the sample on initial VirusTotal submission, indicating very low detection at time of deployment. Note: the original source URL is no longer accessible (404); this analysis is based on the archived PDF attachment.
read more about Pay2Key Ransomware Attack: Companies in Europe and Israel at Risk - Public
Emerging Threat Actor Targets Israeli Private Sector with Pay2Key Ransomware
Check Point Research documents the emergence of Pay2Key, a previously unknown ransomware strain that targeted multiple Israeli corporations in late October and early November 2020. The attacker — believed to be a non-native English speaker and later linked by MITRE to the Fox Kitten threat group — gained initial access through RDP connections, then deployed a custom proxy tool (ConnectPC.exe) on one compromised machine to route all C2 traffic internally, minimizing external network noise. PsExec was used to push the ransomware binary (Cobalt.Client.exe) across the network, achieving full-organization encryption within approximately one hour of initial access. Pay2Key is written in C++ and internally named "Cobalt"; it was under active development at the time of publication, with multiple sample versions compiled within days of each other. The ransomware uses a hybrid AES and RSA encryption scheme, with the RSA public key delivered by the C2 server at runtime — meaning encryption fails if C2 connectivity is unavailable. Each victim received a customized ransom note and encrypted file extension, with demands ranging from 7 to 9 Bitcoin (approximately $110,000–$140,000 at the time). A self-killing mechanism was added in later samples to remove artifacts and reboot the machine post-encryption. Check Point notes the ransomware does not use a packer and was barely detected on VirusTotal at the time of initial analysis, suggesting the actor invested in operational security through proxy design rather than binary obfuscation.
read more about Emerging Threat Actor Targets Israeli Private Sector with Pay2Key Ransomware - Public
Election Interference Exposed: Iranian APT Scans and Exploits U.S. Voter Data
The joint advisory from CISA and the FBI reveals that an Iranian advanced persistent threat (APT) actor targeted U.S. state websites, specifically election websites, in an attempt to influence the 2020 presidential election. The actor employed methods like scanning with Acunetix, exploiting public-facing applications, and using VPN services to masquerade their operations. The APT also attempted to access and distribute U.S. voter registration data, which was subsequently used in disinformation campaigns misleadingly attributed to domestic sources. The operations spanned from September 20 to October 17, 2020, aiming to compromise election infrastructure and gather sensitive information.
read more about Election Interference Exposed: Iranian APT Scans and Exploits U.S. Voter Data - Public
Mermaid APT: A Continuing Threat to Government Agencies
The Mermaid (Infy, Prince of Persia) APT organization, primarily targeting government agencies, has been active since 2010 with consistent attacks and no significant operational gaps. Originating from the Middle East, they utilize the Infy backdoor, evolving into the Foudre backdoor by 2017. The group employs documents with malicious macros, embedding OLE objects to execute the Foudre backdoor via social engineering. Techniques include keylogging, registry modification, scheduled tasks for persistence, and using rundll32 for process injection. The attack also involves substantial data concealment with compressed files and web protocol communication for C2 interactions. The report indicates a sophisticated approach in both evading detection and maintaining long-term access to targeted systems.
read more about Mermaid APT: A Continuing Threat to Government Agencies - Public
Phosphorus Targets Munich Security Conference and T20 Summit Attendees
The Iranian threat actor Phosphorus targeted potential attendees of the Munich Security Conference and the Think 20 (T20) Summit in Saudi Arabia through a series of cyberattacks. The attackers sent spoofed email invitations to former government officials, policy experts, academics, and leaders from non-governmental organizations. Their goal was intelligence collection, and they successfully compromised several high-profile individuals' accounts.
read more about Phosphorus Targets Munich Security Conference and T20 Summit Attendees - Public
Cyber Threats from Iranian APT Actors to U.S. Electoral Integrity
Iranian APTs are suspected of attempting to disrupt the U.S. electoral process to undermine public confidence and create discord among voters. These activities have included the creation of fictitious and spoofed media sites to distribute misinformation about voter issues, utilizing voter-registration data, and spreading anti-American sentiments. The APT groups have exploited critical vulnerabilities such as CVE-2020-5902 and CVE-2017-9248, impacting VPNs and content management systems, to conduct distributed denial-of-service (DDoS) attacks, SQL injection attacks, spear-phishing campaigns, website defacements, and disinformation campaigns.
read more about Cyber Threats from Iranian APT Actors to U.S. Electoral Integrity - Public
Seedworm's Rising Activity: Middle East Targets and PowGoop Tool Connections
The espionage group Seedworm (aka MuddyWater) has been actively targeting government organizations, telecoms, and computer services sectors across the Middle East, including Iraq, Turkey, Kuwait, the United Arab Emirates, Georgia, Afghanistan, Israel, Azerbaijan, Cambodia, and Vietnam. Seedworm's recent activities, linked to the PowGoop tool, involve PowerShell usage, credential dumping, and DLL side-loading. The group establishes connections to its infrastructure using Secure Sockets Funneling and Chisel while deploying PowGoop through remote execution tools. The connection between PowGoop and Seedworm remains tentative, suggesting potential retooling.
read more about Seedworm's Rising Activity: Middle East Targets and PowGoop Tool Connections - Public
Operation Quicksand: MuddyWater's Escalation to Destructive Malware Tactics
In September 2020, the Iranian threat actor MuddyWater launched "Operation Quicksand," as reported by the ClearSky cybersecurity company. This operation targeted Israeli organizations and others across the Middle East and North Africa, aiming to deploy a destructive variant of Thanos ransomware through "PowGoop," a malicious loader disguised as a Google update DLL. By employing spear-phishing, exploiting vulnerabilities, and using sophisticated malware delivery mechanisms, the campaign focused on destructive attacks rather than financial gain, marking a significant shift in MuddyWater's operational intent from espionage to more aggressive tactics.
read more about Operation Quicksand: MuddyWater's Escalation to Destructive Malware Tactics