Latest Update27/08/2026

Threats Feed

  1. Public

    Fox Kitten Campaign: Iranian APTs Target Global Infrastructure via VPN Exploits

    Iranian APT groups APT34 and APT33 jointly operated the Fox Kitten campaign from 2017 to 2019, exploiting VPN vulnerabilities (e.g., Pulse Secure CVE-2019-11510, Fortinet CVE-2018-13379) to breach networks across Israel, the US, Gulf states, and Europe. Targeted sectors included IT, telecommunications, oil and gas, aviation, government, and security. The attackers established persistence using custom and open-source tools, including SSH tunnels, RDP proxies, webshells, and credential dumping via Mimikatz and ProcDump. Tools like Ngrok and Serveo enabled data exfiltration. The infrastructure supported both espionage and potential destructive operations tied to malware such as ZeroCleare and Dustman.

    read more about Fox Kitten Campaign: Iranian APTs Target Global Infrastructure via VPN Exploits
  2. Public

    Deciphering APT33's POWERBAND: A Step Towards Critical Infrastructure Attacks

    Telsy's February 2020 report documents POWERBAND, a new .NET-based Remote Administration Tool attributed to APT33 with medium-to-high confidence. The implant is a heavily obfuscated .NET executable and represents a TTP evolution for APT33 — the first time the group was observed using the .NET runtime environment for a late-stage implant. Telsy named it POWERBAND after the structured URL paths used in its HTTPS C2 communications. The malware closely mirrors APT33's previously known POWERTON backdoor, sharing the same architecture, encryption logic, command parsing methodology, and C2 interaction patterns. On execution, POWERBAND generates a unique victim identifier called BKey, derived from an MD5 hash of the machine name, user domain name, and username (first 24 characters, uppercase). This BKey is used to encrypt all victim fingerprint data — machine name, username, and the BKey itself — and to encrypt and decrypt all C2 traffic. C2 communications use HTTPS POST requests to dailystudy[.]org with three distinct path structures: /album/PBKey/ for command output, /track/BKey/ for file downloads and screenshot exfiltration, and /music/Bkey/band for file uploads. Persistence is achieved via the HKCU SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key. The report notes APT33's observed shift toward targeting critical infrastructure, raising concern about potential disruptive or destructive follow-on operations.

    read more about Deciphering APT33's POWERBAND: A Step Towards Critical Infrastructure Attacks
  3. Public

    RogueRobin DNS Tunneling: A Look at DarkHydrus' Cyber Espionage Tactics

    The RogueRobin malware, developed by the DarkHydrus group, employs DNS tunneling for covert communications in cyberattacks targeting government and educational institutions. The malware appears in two variants: a PowerShell and a .NET executable, both facilitating commands and control operations via encoded DNS queries. This series explores differences in their operation, emphasizing persistence methods and anti-analysis tactics. The technical nuances of RogueRobin, including its innovative DNS record types, highlight its role in sophisticated cyber espionage campaigns.

    read more about RogueRobin DNS Tunneling: A Look at DarkHydrus' Cyber Espionage Tactics
  4. Public

    APT34 Strikes Again: Advanced and Stealthy TONEDEAF 2.0 Targets US Research Services

    APT34 has launched a new campaign targeting United States-based research services company Westat, and its customers, employing a modified toolset. The attack was discovered in late January 2020 and initiated with a spear-phishing operation using a disguised employee satisfaction survey file, survey.xls. Once the victim enabled macros, malicious VBA code executed, extracting and installing a more advanced and stealthy variant of the TONEDEAF malware, TONEDEAF 2.0. The attackers also possibly used a VALUEVAULT implant for browser credential theft. The effort demonstrates APT34's substantial investment in upgrading its toolset to evade future detection.

    read more about APT34 Strikes Again: Advanced and Stealthy TONEDEAF 2.0 Targets US Research Services
  5. Public

    Charming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures

    The Iranian hacking group Charming Kitten, closely associated with Iran's intelligence services, has launched a new series of phishing attacks targeting journalists, political activists, and human rights advocates. These attacks, consistent with the group's previous activities, also aim at private and government institutions, think tanks, academic institutions, and organizations linked to the Baha'i community in the United States, United Kingdom, Saudi Arabia, and Europe. The attackers use fake interview scenarios, impersonating journalists from prominent media outlets like the Wall Street Journal, to gain victims' trust and direct them to phishing sites. These sites capture sensitive information like passwords and two-factor authentication codes. The campaign also involves a backdoor malware named "pdfreader.exe", which alters system settings for remote access and data exfiltration.

    read more about Charming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures
  6. Public

    Shades of OilRig and Chafer in xHunt Campaign's Attack on Kuwaiti Government Sector

    The xHunt Campaign targeted government organizations in Kuwait, compromising a website to create a watering hole. Between May and December 2019, the threat actors injected HTML code to harvest NTLM hashes from visitors, potentially allowing them to infiltrate organizations undetected, steal sensitive information, and even implement backdoors for future access. Concurrent DNS redirect activity was observed, implying an interest in user credential harvesting. The attack involved use of the Responder tool and was linked with previous xHunt activities, including the Hisoka campaign. Intriguingly, some of the infrastructure used in the attack showed overlaps with the activity of known threat groups, OilRig and Chafer.

    read more about Shades of OilRig and Chafer in xHunt Campaign's Attack on Kuwaiti Government Sector
  7. Public

    The Rise of Dustman: Data-Wiping Cyberattacks Traced to Iran

    The Dustman is a data-wiping malware believed to be of Iranian origin, characterized by its use of shared code with another wiper called "ZeroCleare." It exhibits features of blatant copy-pasting from a GitHub repository without credit. The malware includes a muldrop executable containing three encrypted files: a VirtualBox driver from WinNT/Turla, a modified Eldos RawDisk driver, and a malware agent application. The agent application wipes data using the string "Down With Saudi Kingdom Down With Bin Salman." The initial dropper is a modified version of the TDL (Furutaka) project, indicating that the malware targets entities with connections to Saudi Arabia, exploiting vulnerabilities in internet-facing applications.

    read more about The Rise of Dustman: Data-Wiping Cyberattacks Traced to Iran
  8. Public

    Unveiling Dustman: A ZeroCleare Offshoot Wiping Data in the Middle East

    The IBM X-Force IRIS report details the emergence of Dustman, a malware variant in the Wiper class, related to the previously identified ZeroCleare. Discovered in attacks in the Middle East, Dustman is primarily used for destructive purposes, targeting regional organizations. It shares similarities with ZeroCleare in components, including the use of the Turla driver and an EldoS RawDisk driver for disk wiping. However, Dustman shows differences in deployment flow and file names. The malware consists of a binary file, Dustman.exe, which loads the EldoS RawDisk driver, and an agent.exe binary identified as the wiper. Despite these similarities, Dustman features a modified execution order and distinct political messaging, targeting both fixed and removable drives.

    read more about Unveiling Dustman: A ZeroCleare Offshoot Wiping Data in the Middle East
  9. Public

    LYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector

    CyberX Labs' January 2020 deep-dive analyzes DanBot, the primary Remote Access Trojan used by LYCEUM (HEXANE) against oil and gas sector targets in the Middle East. The report documents DanBot's multi-channel C2 architecture: it uses both DNS tunneling — built on a repurposed and renamed version of the Heijden.Dns open-source library — and HTTP/S communication. DanBot is delivered via spearphishing emails containing malicious XLS files with embedded VBA macros (DanDrop). The malware stores its configuration in encrypted files on disk and achieves persistence via Windows scheduled tasks. It supports both file download and file upload, and uses IPv4 and IPv6 addressing for C2 connectivity. C2 traffic is encoded using Base64 and symmetric encryption. The group also uses proxy infrastructure to mask attacker origins. DanBot variants appear to be deployed with a naming convention suggesting Arabic-speaking targets, and contextual indicators point to oil and gas sector victims in the Middle East. IOCs include 5 C2 domains and 80 file hashes across multiple DanBot variants.

    read more about LYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector
  10. Public

    Breathing New Life into MuddyC3: Unveiling the Upgraded Tools of MuddyWater

    In this report, the MuddyC3 tool used by MuddyWater is brought back to life. A group called “Green Leakers” on telegram were first to publish some information on this which triggered the writer of this article to go after the full technical aspect of this tool.This Python2.7 coded tool operates as a C2 server, deploying a PowerShell payload to the targeted system. The payload collects system information and reports back to the C2 server. Notably, the tool includes Base64 encoded PowerShell code to bypass AV detection.

    read more about Breathing New Life into MuddyC3: Unveiling the Upgraded Tools of MuddyWater
  11. Public

    Muddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike

    The Muddy Water threat actor, suspected to be a continuation of the previously reported BlackWater campaign, has been observed distributing malicious documents via spearphishing emails. One document focuses on the nomination of Stephen Moore to the Federal Reserve, likely leveraging current events for social engineering. Another targets the oil and gas sector and features a malicious macro named "H3OpAirStrike," potentially referencing historical Iranian air strikes. Both macros communicate with C2 servers and deploy PowerShell trojans. The malware collects various workstation data and uses Invoke-Obfuscation to evade detection.

    read more about Muddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike
  12. Public

    OilRig's Poison Frog: From PowerShell Backdoors to Cisco AnyConnect Disguises

    Kaspersky's December 2019 report analyzes Poison Frog, a PowerShell-based backdoor used by OilRig (APT34) discovered after scanning archives with a custom YARA rule. The earliest samples date to July 2017, with the malware named after its C2 domain poison-frog[.]club. Each sample is a PE32 executable written in C# that drops an embedded PowerShell script containing two backdoor agents — an HTTP backdoor (59 lines) and a DNS backdoor (335 lines) — and deletes the dropper after execution. The HTTP agent generates a UID from the MAC address or whoami output, then beacons to the C2 to receive commands: execute a shell command and return output, check for and upload a file, or receive and save a file to disk. The DNS agent supports the same command execution and file transfer functions. Persistence is achieved via Windows Task Scheduler. To improve delivery odds, OilRig disguised the malware as a legitimate Cisco AnyConnect VPN application, though implementation errors were present — including a popup appearing on every click and a typo rendering one sample non-functional ("Poweeershell.exe"). Other sloppiness included PDB paths left in binaries and tampered compilation timestamps set to future dates. No specific targeted sectors or countries are named in this report.

    read more about OilRig's Poison Frog: From PowerShell Backdoors to Cisco AnyConnect Disguises
  13. Public

    Decoding Greenbug Group's Command and Control Communications via DNS Tunneling

    DomainTools demonstrates how passive DNS pivoting on ISMDoor's static IPv6 response fingerprints can be used to systematically discover Greenbug's C2 infrastructure — including domains not previously reported. The analysis confirms ISMDoor remained active as recently as November 2019, more than two years after the malware's initial public disclosure in 2017. By querying passive DNS for four known static IPv6 addresses returned during ISMDoor's session establishment protocol (a67d:db8:a2a1:7334:7654:4325:370:2aa3, a67d:db8:85a3:4325:7654:8a2a:370:7334, the all-spaces address 2020:2020:..., and the "Ok" response 4f6b:2020:...), DomainTools identified 19 C2 domains across old and current infrastructure. Most were already sinkholed, but winrepp[.]com was still active on Digital Ocean at the time of publication. Pivoting from that IP and then from outbrainsecupdater[.]com revealed an additional 37 associated domains, including microsoft-publisher[.]com confirmed as an ISMDoor C2 through captured AAAA query data. The report notes that Greenbug's use of DNS tunneling remains effective because many organizations do not monitor DNS traffic for behavioral anomalies. The static IPv6 fingerprints embedded in ISMDoor's session establishment provide a durable detection opportunity regardless of which C2 domain the malware uses — a technique DomainTools notes can be applied to hunt for other DNS-tunneling malware families as well.

    read more about Decoding Greenbug Group's Command and Control Communications via DNS Tunneling
  14. Public

    ZeroCleare Wiper Targets Middle Eastern Energy Sector in Destructive Cyberattack

    IBM's X-Force team has detailed a new destructive malware, ZeroCleare, targeting the energy sector in the Middle East. The wiper, similar to Shamoon, overwrites data and maliciously uses legitimate tools. Attribution points to Iranian state-sponsored groups, possibly a collaboration between ITG13 and another entity. The report highlights the increase in destructive attacks, particularly in the energy sector, and offers mitigation strategies, including the use of threat intelligence, robust security controls and effective backup systems. Finally, it notes the wider geopolitical implications of such attacks.

    read more about ZeroCleare Wiper Targets Middle Eastern Energy Sector in Destructive Cyberattack
  15. Public

    Persistent Exploits in Microsoft Outlook: Iranian Hackers Bypass Security Patches

    Iranian APT groups, notably APT34 and APT33, have exploited the CVE-2017-11774 vulnerability in Microsoft Outlook, using it for espionage and destructive attacks. This exploit involves modifying Outlook's homepage settings via the registry to achieve persistence and remote code execution, bypassing Microsoft's patch. The attacks have targeted sectors globally, leveraging custom phishing documents and Azure-hosted payloads to bypass security measures and maintain control over compromised systems.

    read more about Persistent Exploits in Microsoft Outlook: Iranian Hackers Bypass Security Patches
  16. Public

    Excel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy

    The MuddyWater group conducted a cyberattack campaign during October-November 2019, employing spear phishing emails with macro-infected Excel documents. These emails delivered a file named “Report.xls,” which, when opened and macros were enabled, executed malicious activities including dropping files and creating network connections to a harmful domain. This campaign involved using legitimate Microsoft files for script execution and establishing command and control channels. NetWitness tools were utilized to highlight risky behaviors, registry changes for persistence, and unusual network communications.

    read more about Excel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy
  17. Public

    Credential and Information Theft: APT33's Job Scam Campaign

    Iranian APT33 has been detected running a phishing campaign that employs fake job scams to lure victims. The campaign aims for credential theft, information theft, and unauthorized remote access. While the targeted sectors and countries are not specified, the indicators of compromise involve domain names like "www[.]global-careers[.]org" and filenames such as "JobDescription.zip" and "JobDescription.vbe".

    read more about Credential and Information Theft: APT33's Job Scam Campaign
  18. Public

    Cyber Espionage by APT33 Targets Education, National Security, and Oil Industries

    Trend Micro documents APT33's use of more than a dozen obfuscated C2 servers for extremely narrow targeting, with each botnet comprising only about 12 infected machines. The group runs a multi-layer C2 obfuscation chain: infected bots connect to cloud-hosted proxy domains, which relay traffic to shared webserver backends, which report to dedicated bot data aggregators and controllers — all administered by APT33 operators through a private VPN network with exit nodes rotated frequently. Trend Micro tracked 10 live bot aggregators in fall 2019 and 21 private VPN exit node IPs across late 2018 to late 2019, confirming sustained operations. Confirmed active victims in 2019 include two separate US national security services company locations, two US university victims, a US military-related victim, and multiple Middle East and Asia victims. Oil supply chain compromises confirmed in fall 2018 include a UK-based oil company with servers in the UK and India communicating with an APT33 C2, and a European oil company with an infected server in India for at least three weeks in November–December 2018. APT33 also used a high-ranking European politician's private website for at least two years to send spear phishing emails — with job-lure subjects spoofing aviation and oil companies including al-Salam Aircraft Company, NGAAKSA, DynCorp International, SIPCHEM, Saudi Aramco, and SAMREF — targeting oil supply chain companies including a US military water supply facility. The malware deployed (MsdUpdate.exe, DysonPart.exe — detected as NYMERIA/SCAR variants) is functionally basic: it establishes persistence and downloads additional payloads. All 11 C2 domains listed were registered in 2016–2017 and remained live at time of publication. The VPN exit nodes were also used for reconnaissance against oil exploration companies and military hospitals in the Middle East and a US oil company.

    read more about Cyber Espionage by APT33 Targets Education, National Security, and Oil Industries
  19. Public

    Leaked Toolkit Exposes APT34’s Sophisticated Cyberattacks

    This NSFOCUS report details an analysis of a leaked toolkit belonging to the APT34 hacking group, also known for its similarities to OilRig. The report focuses on the toolkit's components, including Trojans such as Glimpse and PoisonFrog, and Webshells used for privilege escalation and data exfiltration, primarily targeting the energy and financial sectors, particularly in China and the Middle East. The analysis details the functionality and communication methods of the tools, which use DNS tunneling for command and control.

    read more about Leaked Toolkit Exposes APT34’s Sophisticated Cyberattacks
  20. Public

    TA407’s Phishing Campaigns Continue Targeting Universities Globally

    TA407 (Silent Librarian) has consistently targeted universities, particularly in the US, Europe, and North America, in credential phishing campaigns. Using tailored phishing pages mimicking university login portals, the group compromises accounts to steal academic data, intellectual property, and user credentials. Between 2013 and 2017, TA407 caused over $3.4 billion in intellectual property losses, affecting thousands of university accounts worldwide. The group exploits Freenom domains and various URL shorteners, including university-based services, to distribute phishing links and expand their reach within academia.

    read more about TA407’s Phishing Campaigns Continue Targeting Universities Globally
  21. Public

    Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence

    ClearSky's October 2019 report documented an active Charming Kitten (APT35/Phosphorus) campaign targeting US presidential campaign staff, government officials, journalists, Iranian dissidents, and civil society figures including the Baha'i community. The campaign used four distinct impersonation vectors: fake Google Drive sharing links, SMS phishing messages, spoofed account login-attempt alerts, and fake social network profiles impersonating known contacts. Malicious links led to credential-harvesting pages mimicking Google, Yahoo, Facebook, and Instagram logins, hosted on a network of actor-registered domains. The group abused Google Sites and URL shorteners to obfuscate malicious destinations. Microsoft identified 99 domains tied to the operation (tracked internally as Phosphorus/Strontium) and obtained a court order to seize them. IOC overlaps with prior Certfa reporting confirm continuity of infrastructure across Charming Kitten campaigns dating to 2018. The campaign is assessed as part of Iran's broader effort to conduct cyber-enabled political intelligence collection ahead of the 2020 US presidential election.

    read more about Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence
  22. Public

    Tortoiseshell Targets U.S. Military Veterans with Malicious Job Seeking Website

    Tortoiseshell deployed a fake website targeting U.S. military veterans seeking jobs. The site tricked users into downloading a malicious app that served as a malware downloader, deploying spying tools and other malware. The fake website had users download a fake installer, which downloaded two binaries: a reconnaissance tool and a Remote Administrative Tool (RAT). The reconnaissance tool collected extensive information about the victim's machine, while the RAT allowed further remote control.

    read more about Tortoiseshell Targets U.S. Military Veterans with Malicious Job Seeking Website
  23. Public

    APT33 Expands its Cyberattack Scope Beyond the Middle East

    HYAS Threat Intelligence identified a cluster of APT33 campaign infrastructure being actively built out ahead of imminent attacks on targets beyond the group's traditional Middle East focus. In mid-2019, APT33 — also tracked as Elfin, Holmium, Magnallium, and Refined Kitten — was observed targeting financial services and advanced technology companies in the United States and other countries, expanding beyond its historic emphasis on energy, aerospace, and defense. HYAS identified 11 high-confidence (95%+) and 9 moderate-confidence (75%+) domains linked to APT33 infrastructure, several of which were flagged before they were put into active use — including customermgmnt[.]net, later confirmed by US Cyber Command as a malware delivery point exploiting CVE-2017-11774 (a Microsoft Outlook vulnerability). The report reflects increased Iranian APT activity tied to escalating geopolitical tensions, with APT33 operating in parallel with APT34, APT35, and MuddyWater.

    read more about APT33 Expands its Cyberattack Scope Beyond the Middle East
  24. Public

    Unraveling PoisonFrog: DNS Tunneling Tactics of OilRig Explored

    The IronNet Threat Research team explored PoisonFrog malware, revealing its DNS tunneling capabilities for covert communications. This PowerShell-based malware, linked to the OilRig/APT34 group, abuses DNS protocol to establish command and control channels, avoiding direct malicious infrastructure connections. PoisonFrog crafts DNS queries to register, receive tasks, and transmit data, leveraging recursion for seamless integration into victims' DNS infrastructures. Despite its sophisticated DNS usage, PoisonFrog includes an HTTP fallback for command and control, indicating preparedness for DNS communication failure.

    read more about Unraveling PoisonFrog: DNS Tunneling Tactics of OilRig Explored