Latest Update27/08/2026

Threats Feed

  1. Public

    Silent Librarian Resumes Spearphishing Attacks Against Global Universities

    Silent Librarian (aka TA407/COBALT DICKENS) has resumed its annual spearphishing campaign targeting universities worldwide for the 2020-2021 academic year. The group seeks to steal research and intellectual property using phishing websites that mimic legitimate university domains. Recent campaigns have featured domains with altered top-level domains such as ".me", ".tk" and ".cf", often hosted via Cloudflare to disguise the true origin, which includes servers based in Iran. This follows their indictment by the US Department of Justice in 2018 for cyber attacks on academic institutions worldwide.

    read more about Silent Librarian Resumes Spearphishing Attacks Against Global Universities
  2. Public

    Lyceum APT Targets Middle Eastern Oil, Gas, and Telecom Sectors

    The Lyceum APT targets the oil, gas and telecommunications sectors in the Middle East, focusing on credential theft and network infiltration through a multi-stage attack chain. The initial infection involves malicious Microsoft Office documents that deploy DanDrop, a VBA-based malware dropper that installs DanBot, a remote access Trojan used for ongoing control. The group also uses PowerShell scripts, including keyloggers and credential decryption tools, to gather sensitive data from Active Directory and RDCMan configurations. The sophisticated attack chain used by this cybercrime group highlights the ongoing threat to critical infrastructure in the Middle East.

    read more about Lyceum APT Targets Middle Eastern Oil, Gas, and Telecom Sectors
  3. Public

    Iranian APT MERCURY Exploits Zerologon in Persistent Cyber Campaigns

    Microsoft reports that the Iranian APT group MERCURY (aka MuddyWater) is actively exploiting the Zerologon vulnerability (CVE-2020-1472) to compromise Active Directory services. Known for targeting Middle Eastern governments for data exfiltration, MERCURY has also exploited the SharePoint vulnerability (CVE-2019-0604) to implant web shells for persistent access. These attacks often involve Cobalt Strike payloads and lateral movement within networks, focusing on domain controllers. Despite patches released in 2020, exploitation attempts remain widespread, highlighting the need for robust patch management. MERCURY's activities highlight the ongoing threat to governments and other critical sectors in the Middle East.

    read more about Iranian APT MERCURY Exploits Zerologon in Persistent Cyber Campaigns
  4. Public

    Rampant Kitten: Iranian Cyber Espionage Campaign Exposed

    Check Point Research uncovered an ongoing Iranian espionage campaign, Rampant Kitten, targeting Iranian expats and dissidents. The attackers used Windows infostealers to steal personal documents and access Telegram and KeePass accounts. They employed Android backdoors to intercept SMS-based 2FA codes and record audio, and also created Telegram phishing pages. The campaign's initial infection vector involved a malicious document exploiting external template loading. Key targets included anti-regime organizations and minority resistance groups such as AFALR and Azerbaijan National Resistance Organization. The malware utilized SOAP for communication and featured sophisticated persistence and data exfiltration techniques.

    read more about Rampant Kitten: Iranian Cyber Espionage Campaign Exposed
  5. Public

    Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign

    Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.

    read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
  6. Public

    Pioneer Kitten's Multi-Sector Cyber Offensive in the United States

    Pioneer Kitten (also tracked as UNC757), an Iran-based threat actor, has been conducting a sustained cyber offensive against US organizations across the IT, government, healthcare, financial, insurance, and media sectors since early 2019. The group gains initial access by exploiting known vulnerabilities in VPN appliances — primarily Pulse Secure (CVE-2019-11510), Citrix (CVE-2019-19781), and F5 BIG-IP (CVE-2020-5902). Once inside, the actor installs web shells for persistent access, uses tunneling tools including Ngrok, FRP, and Chisel to bypass network controls, and harvests credentials. What makes Pioneer Kitten unusual is its dual motivation: it collects intelligence in support of Iranian government priorities while also selling access to compromised US networks on criminal hacker forums. CISA flagged the actor's potential capability and intent to deploy ransomware on victim networks, elevating the threat beyond traditional espionage.

    read more about Pioneer Kitten's Multi-Sector Cyber Offensive in the United States
  7. Public

    TRACER KITTEN's Sophisticated Attack on EMEA Telecommunications Network

    In April 2020, Iran-based threat actor TRACER KITTEN targeted a telecommunications company in the EMEA region, leveraging valid credentials and custom backdoors for persistent access and C2 communications. The adversary employed SSH tunnels, masqueraded tools, and rogue Windows services to evade detection. Credential theft attempts involved LSASS dumps via comsvcs.dll and a modified Mimikatz. Reconnaissance was extensive, using native Windows tools to enumerate users, groups, and services, followed by a pass-the-hash attempt with Invoke-TheHash. Early detection allowed defenders to mitigate potential data exfiltration.

    read more about TRACER KITTEN's Sophisticated Attack on EMEA Telecommunications Network
  8. Public

    Shifting Domains: APT33's Evolving Network Infrastructure

    ThreatConnect Research Team documents a brief infrastructure pivot observation: four APT33 C2 domains previously identified in Trend Micro's 2019 report on obfuscated APT33 botnets (zeverco[.]com, service-eset[.]com, simsoshop[.]com, qualitweb[.]com) began resolving to a new IP address, 109.230.199[.]157, starting in late July 2020. ThreatConnect explicitly notes that it is unknown whether this IP address is a sinkhole, a parking IP, or still under APT33's operational control, and whether the domains are still being used by APT33. Several additional domains not previously associated with APT33 also began resolving to the same IP during the same period: publicsecur[.]com, akadnsplugin[.]com (registrant: joshua.toon1978@mail[.]com), service-houston[.]com, support-newyork[.]com, and ocsp-support[.]com (registrant: warren.jones2626@mail[.]com). These additional domains were registered through THCservers, a suspicious reseller previously used by multiple state and criminal actors. ThreatConnect notes a possible further association between ocsp-support[.]com and two additional domains — prefmsedge[.]com and tracking-protection[.]net — based on reuse of the "Warren Jones" email address string in registrant data (registered through AminServe rather than THCservers). This is a brief infrastructure observation published as part of ThreatConnect's weekly Research Roundup; the same edition also covers unrelated RedDelta PlugX and Emotet activity. Attribution to APT33 for the newly identified domains remains unconfirmed.

    read more about Shifting Domains: APT33's Evolving Network Infrastructure
  9. Public

    PIONEER KITTEN: Exploiting VPN Vulnerabilities to Target Sensitive Sectors

    Pioneer Kitten, an Iran-based adversary active since 2017, targets North American and Israeli entities of intelligence interest, including technology, government, defense, and healthcare sectors. The group relies on exploiting vulnerabilities in VPNs and network appliances (e.g., CVE-2019-11510, CVE-2019-19781, CVE-2020-5902) for initial access, and uses open-source tools like Ngrok and SSHMinion for SSH tunneling and RDP for hands-on activity. Recently, PIONEER KITTEN was seen selling access to compromised networks on underground forums, indicating an attempt to diversify revenue streams.

    read more about PIONEER KITTEN: Exploiting VPN Vulnerabilities to Target Sensitive Sectors
  10. Public

    Charming Kitten Uses WhatsApp and LinkedIn for Targeted Phishing Attacks

    ClearSky researchers documented a new Charming Kitten (APT35) campaign that, starting July 2020, expanded their established journalist-impersonation playbook to include WhatsApp and LinkedIn as primary contact channels — a first for this group. Attackers impersonated Persian-speaking journalists from Deutsche Welle and the Jewish Journal, initiating contact via email before moving conversations to WhatsApp using German phone numbers (+49 prefix) and voice calls to build credibility. If victims declined to share their phone number, a fake LinkedIn profile (such as "Marcy Oster" or "Helen Cooper") was used to continue the approach. The ultimate goal was credential theft: victims were invited to a fake webinar via a personalized phishing link on the legitimate Deutsche Welle domain (akademie.dw[.]de), leading to a spoofed Outlook login page that harvested university credentials, including bypassing 2FA. In some cases, a malicious file attachment was also sent via LinkedIn. Targets included Israeli academics from Haifa and Tel Aviv Universities, US government officials and former State Department employees, the Baha'i community, and COVID-19-related organizations. Each victim received a uniquely personalized phishing link tied to their specific email address. Deutsche Welle confirmed to ClearSky that none of the impersonated journalists contacted the victims.

    read more about Charming Kitten Uses WhatsApp and LinkedIn for Targeted Phishing Attacks
  11. Public

    OilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms

    OilRig targeted a telecommunications organization in the Middle East using a variant of their RDAT tool, featuring a novel email-based command and control (C2) channel that employs steganography. This method hides commands and data within bitmap images attached to emails, making detection difficult. The attack involved custom Mimikatz tools for credential dumping, Bitvise for SSH tunneling, and PowerShell downloaders. RDAT has been under development since 2017, evolving to include DNS tunneling and Exchange Web Services (EWS) for C2 communications. The use of steganographic images in emails represents a sophisticated evasion technique.

    read more about OilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms
  12. Public

    Iranian Threat Group ITG18 Exposed: Targeting US Military and Political Campaigns

    IBM X-Force IRIS uncovered extensive details on ITG18 through operational errors. Over 40 GB of data and videos revealed ITG18’s targeting of U.S. Navy and Hellenic Navy personnel, U.S. presidential campaigns, pharmaceutical companies, and Iranian-American figures. The group employed credential harvesting, phishing, and email compromise, often using Zimbra to manage compromised accounts. ITG18's operations align with Iranian strategic interests, leveraging personal accounts to gather sensitive data on military operations and geopolitical targets. Multifactor authentication posed challenges, causing operators to pivot to new targets.

    read more about Iranian Threat Group ITG18 Exposed: Targeting US Military and Political Campaigns
  13. Public

    Tracking APT39 and APT34: Innovations in C2 Server Profiling

    In October 2019, Aaron Stephens introduced the SCANdalous project, which automates the profiling of command and control (C2) servers used by threat groups. Prior to automation, analysts manually identified servers linked to groups like APT39 and APT34. APT39 employed SSH tunneling and specific server characteristics to evade detection, while APT34 used QUADAGENT malware and PowerShell-based tools like POSHC2 and POWERTON. These efforts led to early identification of malicious infrastructure, improving threat tracking capabilities.

    read more about Tracking APT39 and APT34: Innovations in C2 Server Profiling
  14. Public

    APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks

    HYAS provides a July 2020 update on APT33 activity during the COVID-19 pandemic, a period during which public attention to Iranian threat groups had diminished despite continued operations. APT33 — also known as Refined Kitten, Magnallium, and Holmium — maintained its infrastructure-building tempo throughout the pandemic, with HYAS identifying new suspicious domain registrations consistent with prior APT33 TTPs over a 90-day monitoring window. The group continued targeting US organizations in the aviation, petrochemical, and defense contractor sectors using multi-stage attacks: weaponized documents, exploitation of the Microsoft Outlook vulnerability CVE-2017-11774, and PowerShell backdoors delivered from domains mimicking legitimate business services. A key example — customermgmt[.]net — was publicly confirmed by US Cyber Command in July 2019 as an active APT33 malware delivery point. The report contextualizes this activity against escalating Iran-West tensions: the collapse of the Iran nuclear deal, the January 2020 assassination of Qasem Soleimani, and the subsequent downing of a civilian aircraft near Tehran.

    read more about APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks
  15. Public

    RASPITE Targets Electric Utilities with Credential Theft and Remote Access

    Dragos identified RASPITE as a distinct activity group targeting electric utilities since at least early-to-mid 2017, with confirmed targeting in the US, Europe (including Saudi Arabia), and East Asia (including Japan). The group overlaps significantly with Symantec's LEAFMINER and uses identical initial access methodology to DYMALLOY and ALLANITE: compromising legitimate websites to embed hidden resource links that force visitors' browsers to initiate SMB connections, transmitting Windows NTLM credential hashes to attacker-controlled servers for offline cracking. Once credentials are obtained, RASPITE deploys install scripts for a malicious Windows service that beacons back to actor-controlled infrastructure, enabling remote access via RDP. The group spoofs domains for legitimate IT services to blend C2 traffic into normal network activity. While RASPITE's operations focus exclusively on IT networks within ICS-operating entities — particularly electric utilities — and it has not demonstrated ICS-specific or disruptive capabilities to date, Dragos assesses its targeting methodology and persistence as preparatory activity for potential future ICS operations. The group's focus on electric utility initial access operations mirrors the early stages seen before more impactful ICS attacks.

    read more about RASPITE Targets Electric Utilities with Credential Theft and Remote Access
  16. Public

    Iranian Chafer APT Targets Kuwait and Saudi Arabia’s Critical Sectors

    Bitdefender's May 2020 whitepaper documents two Chafer APT campaigns dating to 2018 against air transportation and government targets in Kuwait and Saudi Arabia. The Kuwait attack was the more sophisticated of the two. Initial access was likely achieved via spearphishing with shellcode-laden documents executing Metasploit reverse TCP payloads. Attackers then deployed a full toolkit: CrackMapExec for network scanning, credential dumping, and account enumeration; Mimikatz (including a SafetyKatz variant and a customized version) for credential dumping; a modified Plink (wehsvc.exe) installed as a Windows service for C2 and tunneling; custom proxy tools (mini.exe, mfevtpse.exe) using SOCKS5 over HTTP disguised with bing.com host headers; and custom Python-based RATs (snmp.exe/imjpuexa.exe) using DNS and HTTP C2 channels that marshal packets to resemble legitimate DNS/HTTP traffic. A MechaFlounder-variant RAT (drivers.exe/dbxservice.exe) established persistence via scheduled tasks ("Defender Update" / "Service Update") and exfiltrated data to Dropbox — each victim had a separate folder named by machine+username combination. The RTLO character (U+202E) was used in filenames to spoof file extensions for defense evasion. Attackers created their own user accounts on compromised machines and operated primarily on weekends (Friday/Saturday — the regional weekend), suggesting awareness of Middle Eastern business hours. Scanning tools included a modified nbtscan variant (xnet.exe) and etblscanner.exe, an EternalBlue scanner written in Python. Shared PDB paths and compiler artifacts link xnet.exe to Remexi (mas.dll), connecting this campaign to prior Chafer infrastructure. The Saudi Arabia attack was simpler: social engineering led a user to execute a RAT directly from their Downloads folder (parent process: explorer.exe), suggesting the user was tricked into double-clicking a malicious file.

    read more about Iranian Chafer APT Targets Kuwait and Saudi Arabia’s Critical Sectors
  17. Public

    Suspected APT33 Cyber Infrastructure Identified in Recent Domain Registrations

    The report uncovers suspicious network infrastructure possibly linked to APT33, highlighting the registration of the domain taskreminder[.]net and its association with the ns1.realhosters.com name server and OVH hosting. It draws parallels with previously identified APT33 infrastructure, emphasizing the pattern of using specific name servers and hosting services. Additionally, the report identifies domains spoofing Poste Italiane and “msupdate” themed domains, suggesting potential credential harvesting and malicious software distribution activities.

    read more about Suspected APT33 Cyber Infrastructure Identified in Recent Domain Registrations
  18. Public

    Greenbug's Cyber Espionage Campaign Against South Asian Telecoms

    The Greenbug espionage group is conducting an information-gathering campaign against telecommunications companies in South Asia. Using a mix of off-the-shelf tools and living-off-the-land techniques, the group primarily employs email as the initial infection vector. Notable files used for infection are proposal_pakistan110.chm:error.html and GRUNTStager.hta, often delivered through compromised websites via spearphishing. The group aims to gain access to database servers, leveraging tools like Covenant and custom malware like Trojan.Ismdoor. They have been observed using various PowerShell commands, Mimikatz, and Cobalt Strike, alongside multiple webshells. Living-off-the-land utilities such as Plink and Bitvise were used to establish tunnels back to attacker-controlled infrastructure.

    read more about Greenbug's Cyber Espionage Campaign Against South Asian Telecoms
  19. Public

    The Espionage Arsenal of Nazar's Backdoor

    The Nazar APT's backdoor, showcases a suite of espionage tools used for malicious activities. It employs a passive approach, utilizing the discontinued Packet Sniffer SDK (PSSDK) for communication. Key capabilities include a keylogger that saves data in %WINSYSDIR%\report.txt, system shutdown through an OLE object, screen capture saved in %CWD%\z.png, audio recording saved as %WINSYSDIR%\music.mp3, and enumeration of drives, files, and installed programs with results stored in %WINSYSDIR%. Additionally, it can remove files, list devices, perform a ping operation, and gather OS information. This malware is specifically designed for espionage, indicating a focus on data extraction and system information discovery.

    read more about The Espionage Arsenal of Nazar's Backdoor
  20. Public

    Nazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors

    The Nazar APT, active since at least 2010, employs a modular toolkit for cyber espionage. Its main dropper registers multiple DLLs as OLE controls in the Windows registry using 'regsvr32.exe'. It includes a service disguised as 'svchost.exe' for persistence, and uses custom and repurposed libraries for various functionalities like keylogging, audio capture, and screen capture. Nazar's droppers, built with Chilkat's 'Zip2Secure', are often misidentified by antivirus software. A notable feature is EYService, a passive backdoor listening on UDP port '1234', enabling commands like ping response, victim info requests, and file downloads. Additionally, it uses a packet sniffer for potentially sophisticated command-and-control activities. The report, however, does not specify targeted countries or sectors.

    read more about Nazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors
  21. Public

    Operation Mermaid: A Decade of Targeted APT Attacks on Government Entities

    Operation Mermaid, an APT campaign active since April 2010, targeted government entities, specifically the Denmark Embassy and the Ministry of Foreign Affairs of Denmark. This six-year operation utilized phishing emails and watering hole attacks to deliver malicious code, evidenced by 284 malicious samples and 35 C&C domains. Analysis revealed the primary aim was data theft from English and Persian speaking countries. The SD RAT malware, disguised as legitimate files, played a key role in these attacks, featuring keylogging and data exfiltration capabilities. Differences in malware versions and tactics, including a unique check for Avast antivirus, suggest evolving strategies to evade detection.

    read more about Operation Mermaid: A Decade of Targeted APT Attacks on Government Entities
  22. Public

    APT34 Strikes Lebanese Government with MailDropper Implant

    Telsy's threat intelligence team provides the most detailed technical analysis of the MailDropper implant used by APT34 against Lebanese government entities in early 2020, published simultaneously with Yoroi's parallel report on the same sample. The infection begins with a spearphishing Excel document containing a VBA macro that drops monitor.exe into a hidden .Monitor folder under C:\Users\Public\. A scheduled task named "SystemErrorReporter" runs the payload every minute. The monitor.exe binary contains hardcoded credentials for a compromised Exchange account (redacted as media@xxx.local) belonging to the targeted Lebanese government institution. Commands are retrieved by polling the Exchange Inbox for emails with the subject "Resume7AKF1PMAVAHI7SYK"; matching emails have Base64-encoded command payloads in their attachments, which are extracted and executed via ExecAllCmds. After processing, each email is permanently deleted with the HardDelete flag — ensuring processed commands leave no trace in the trash folder. Results are returned as new emails with subject "Great! 7AKF1PMAVAHI7SYK" + date, body "This is our reusme!" (syntax error preserved as a forensic indicator), with command output base64-encoded in an attachment named resume.txt. If the Exchange server is unavailable, MailDropper falls back to a backup HTTP C2 at godoycrus[.]com. All data exchanged with the C2 is encrypted using AES+RSA hybrid encryption: data is AES-encrypted with an auto-generated key, the key is then RSA-encrypted and prepended to the payload. Telsy draws four specific parallels to DNSpionage (Lebanon targeting, Excel macro delivery, dot-prefixed hidden folder, .NET payload) as supporting attribution to APT34. Telemetry at time of publication confirmed the implant was in use exclusively within Lebanon.

    read more about APT34 Strikes Lebanese Government with MailDropper Implant
  23. Public

    APT34 Strikes Again: Government Sector in Lebanon Under Karkoff Attack

    Yoroi (Cybaze ZLab) identifies an updated Karkoff implant used by APT34 in a new espionage campaign targeting the Lebanon government, active from at least January 27, 2020 — the date godoycrus[.]com was registered. The campaign connects to a 2018–2019 chain: Cisco Talos had documented the original DNSEspionage campaign against Lebanon and UAE, then in April 2019 linked it to APT34 and named the implant Karkoff. This 2020 variant introduces two key changes. First, it implements a reconnaissance guardrail: before dropping the final payload, Karkoff collects the hostname, domain name, and OS version and only proceeds if the target matches a specific profile — significantly reducing exposure to sandbox and automated analysis environments. Second, the C2 channel runs entirely through a compromised Lebanon government Microsoft Exchange server: Karkoff connects using an Exchange client UserAgent string, retrieves commands delivered as email attachments in replied messages, and decodes them from a custom-encoded email body string. Delivery begins with a malicious Excel macro (hash: 926e29f9...) that extracts a base64-encoded payload from the file body, decodes it, writes monitor.exe to C:\Users\public\.Monitor\, and establishes persistence via a scheduled task named SystemExchangeService. Yoroi assesses APT34 likely used the Jason brute-force tool — leaked in late 2019 and part of the Lab Dookhtegan APT34 tool dump — to obtain Exchange credentials before deploying Karkoff. Telsy published a parallel analysis of the same sample on the same day. Yoroi provides two YARA rules for detection: Karkoff_Attack_2020_Excel_macro (matching EncodedData0, NewTask9 strings) and Karkoff_Campaign_2020 (matching SystemExchangeService, getWindowsVersion, GetCommands). Source URL is no longer directly accessible; this analysis is based on the archived PDF attachment.

    read more about APT34 Strikes Again: Government Sector in Lebanon Under Karkoff Attack
  24. Public

    Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security

    In a series of espionage-focused campaigns, the Cobalt Ulster threat group, linked to the Iranian government, targeted governmental and intergovernmental organizations across Turkey, Jordan, Iraq, Georgia, and Azerbaijan from mid-2019 to mid-January 2020. These attacks primarily involved spearphishing with malicious attachments and links to compromised websites. The group used various techniques, including obfuscated macros in Excel files, VBScript, and PowerShell scripts for initial access and persistence. The campaigns featured sophisticated methods like DNS tunneling for command and control, and the use of tools for credential harvesting and establishing reverse SSL tunnels, indicating a high level of technical proficiency and strategic planning.

    read more about Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security