Latest Update27/08/2026

Threats Feed

  1. Public

    Tortoiseshell Group Targets IT Providers in Saudi Arabia: Supply Chain Attacks Uncovered

    The Tortoiseshell group has targeted IT providers in Saudi Arabia since at least July 2018, focusing on supply chain attacks to compromise the IT providers' customers. The group deployed both custom and off-the-shelf malware, infecting an unusually large number of computers in targeted attacks. The custom malware, Backdoor.Syskit allowed for downloading and executing additional tools and commands. The attackers used various information-gathering tools, achieving domain admin-level access on at least two organizations, and it is suspected they compromised a web server to deploy malware onto the network.

    read more about Tortoiseshell Group Targets IT Providers in Saudi Arabia: Supply Chain Attacks Uncovered
  2. Public

    Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign

    The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.

    read more about Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign
  3. Public

    OilRig's Use of BONDUPDATER: A Stealthy Cyber Espionage Campaign on Bahrain

    NETSCOUT ASERT captured live command and control traffic from an updated BONDUPDATER variant targeting the Office of the First Deputy Prime Minister of Bahrain via spearphishing emails — activity the team attributes to OilRig (APT34). ASERT reverse-engineered the malware's C2 protocol in real time, documenting two key mechanisms. Command delivery uses DNS TXT records: the attacker's nameserver returns base64-encoded commands (with modified padding characters) in a structured format prefixed by a 5-character identifier and delimited by a ">" character, allowing multi-part commands to be reassembled on the victim machine. Data exfiltration uses DNS A record queries, with output stuffed into custom subdomains using a distinctive nibble-splitting obfuscation technique: each byte of data is split into its two 4-bit nibbles, with first nibbles placed in one list and second nibbles in another, joined end-to-end to form subdomain strings. Exfiltration sessions are bracketed by "COCTab" (start) and "COCTabCOCT" (end) markers in the subdomain, alongside a command identification value allowing the attacker to map responses to issued commands. ASERT observed the attacker running whoami and ipconfig /all as initial reconnaissance commands. The C2 domain used was withyourface[.]com. NETSCOUT notes that BONDUPDATER's continuous development — including this new obfuscation layer — indicates OilRig's ongoing investment in evading detection, and recommends monitoring DNS traffic for abnormally long domain names and scanning DNS A record subdomains for the "COCTab" string as a specific detection indicator.

    read more about OilRig's Use of BONDUPDATER: A Stealthy Cyber Espionage Campaign on Bahrain
  4. Public

    COBALT DICKENS Targets Global Universities in Persistent Phishing Campaign

    COBALT DICKENS, linked to Iran's Mabna Institute, continues to launch large-scale phishing campaigns targeting universities around the world. In July and August 2019, the group launched a global operation that compromised more than 60 universities in the US, UK, Australia, Canada, Hong Kong and Switzerland. Using spoofed login pages for library resources, they stole login credentials through phishing emails. The attackers registered domains using free TLDs and used legitimate SSL certificates to make their phishing infrastructure more convincing. Despite multiple takedowns and indictments, COBALT DICKENS remains active, targeting over 380 universities in more than 30 countries and using free tools and public services to maintain its operations.

    read more about COBALT DICKENS Targets Global Universities in Persistent Phishing Campaign
  5. Public

    How the GreenBug Group Exploits DNS Tunneling with Ismdoor Malware

    The Ismdoor malware, linked with the GreenBug group, continues its cyberattacks using DNS tunneling to evade detection, communicate with command and control servers, and exfiltrate data. Black Lotus Labs detected recent spikes in such activities related to the domain basnevs[.]com, associated with Ismdoor. The malware uses encoded subdomains for data exfiltration and receives hex-encoded messages from the C2. An increase in tunneling activity suggests that too many organizations still allow unmonitored DNS traffic, which amplifies the risk of successful DNS tunneling attacks. The report doesn't explicitly mention specific targeted countries or sectors.

    read more about How the GreenBug Group Exploits DNS Tunneling with Ismdoor Malware
  6. Public

    Inside Hexane: Sophisticated Cyber Tools and Tactics Targeting Critical Industries

    Hexane (LYCEUM), a threat actor primarily targeting the Middle East’s oil, gas, and telecommunications sectors, has expanded its attack methods. Using spear-phishing emails with malicious Excel macros, the group delivers DanBot, a RAT capable of DNS and HTTP-based command and control, file transfer, and command execution. Additional tools include a PowerShell-based keylogger, credential decryption scripts, and LDAP data-extraction tools targeting Active Directory accounts. They employ social engineering, password spraying, and DNS tunneling to maintain access, frequently rotating C2 infrastructure. The group’s activity indicates continued cyber threats within these critical sectors.

    read more about Inside Hexane: Sophisticated Cyber Tools and Tactics Targeting Critical Industries
  7. Public

    LYCEUM's Cyber Campaign on Middle Eastern Sectors: An In-depth Analysis

    Secureworks CTU's August 2019 report introduces LYCEUM (also known as HEXANE), an emerging Iranian-linked threat group that began targeting oil and gas organizations in the Middle East in May 2019, with earlier activity against South African targets dating to April 2018. The group gains initial access via password spraying or brute-force attacks against corporate email accounts, then uses the compromised accounts to send spearphishing emails with malicious Excel attachments to executives, HR staff, and IT personnel. The Excel files embed a VBA macro dropper called DanDrop that extracts, Base64-decodes, and installs DanBot — a C#/.NET RAT using both DNS (IPv4 A and IPv6 AAAA records) and HTTP channels for C2 communication — via a scheduled task. Post-intrusion tools include kl.ps1 (a PowerShell keylogger storing captured keystrokes as Base64 in scheduled-task deployments), Decrypt-RDCMan.ps1 (a PoshC2 component used to decrypt stored RDP credentials within one hour of initial access), and Get-LAPSP.ps1 (a PowerView-based LDAP account enumeration script). DanBot contains a consistent typo in its HTTP User-Agent — "Accept-Enconding" — which serves as a reliable network detection indicator. LYCEUM registered C2 infrastructure through PublicDomainRegistry.com, Web4Africa, and Hosting Concepts B.V., using security- and web-technology-themed domain names. IOCs include 9 C2 IP addresses, 10 domains, and 3 file hashes for a DanBot variant named AdobeReport.exe. Secureworks noted stylistic similarities to COBALT GYPSY (OilRig/APT34) and COBALT TRINITY (Elfin/APT33) but found insufficient evidence for attribution at time of publication.

    read more about LYCEUM's Cyber Campaign on Middle Eastern Sectors: An In-depth Analysis
  8. Public

    Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations

    Cyware's August 2019 overview profiles APT34 (also known as Helix Kitten, OilRig, and Greenbug), an Iranian state-sponsored threat group active since 2014. The group targets organizations across the Middle East and beyond, focusing on finance, government, energy, telecommunications, IT, military, healthcare, and education sectors. APT34 is assessed to collect intelligence that serves Iran's economic and geopolitical interests. Over a five-year period, its campaigns evolved from spearphishing Middle Eastern banks with weaponized Excel attachments to broader global operations. Notable campaigns include exploitation of CVE-2017-0199 (OLE remote code execution) against Israeli institutions in April 2017, and CVE-2017-11882 (Office memory corruption) in October 2017 UAE government targeting. The group deployed a large custom malware arsenal including Helminth, OopsIE, POWRUNER, BONDUPDATER, Karkoff, ISMAgent, Poison Frog, Neptun, and web shells (TwoFace, RGDoor, HyperShell, HighShell, RunningBee, PhpSpy). In April 2019, the threat actor "Lab Dookhtegan" publicly leaked APT34 tools and victim lists. In June 2019, Russian group Turla was discovered hijacking APT34 infrastructure to deliver its own Neptun backdoor. A total of 101 C2 IPs, 63 domains, 117 shell URLs, and 9 file hashes are documented as indicators of compromise from this report.

    read more about Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations
  9. Public

    APT33 Elevates C2 Capabilities with New PowerShell Malware

    Norfolk InfoSec analyzed a custom PowerShell backdoor linked to APT33's mid-2019 campaign, identified through infrastructure pivots on the confirmed C2 domain backupaccount[.]net — a domain publicly flagged by US Cyber Command, ClearSky, and FireEye. The malware defines 14 functions and implements a full-featured C2 framework: it communicates with its control server via JSON-masked HTTP requests, supports active and silent operating modes with dynamically adjusted polling intervals (5–10 seconds active, 45–70 minutes silent), and implements two separate persistence mechanisms — WMI event filters and HKCU registry Run keys (smrsservice.exe). Core capabilities include file upload and download (with recursive directory traversal), screenshot capture, privilege checking, credential-related commands (SAM hive, LDAP, and an external invoke-pass module), arbitrary PowerShell command execution via invoke-expression, and encrypted C2 communications. The malware's modular command structure — with operator-controlled mode switching and clean-up via a paired "left" command — reflects a mature, operationally disciplined C2 design consistent with APT33's known capability level.

    read more about APT33 Elevates C2 Capabilities with New PowerShell Malware
  10. Public

    APT34's Phishing Strategy With New Malware Families Targeting Key Sectors

    Mandiant detected a phishing campaign by APT34, an Iranian-nexus threat actor, in late June 2019. The actor, posing as a member of Cambridge University, delivered malicious documents via LinkedIn and introduced three new malware families. The primary industries targeted by this campaign were Energy and Utilities, Government, and Oil and Gas. APT34 is notably active in the Middle East, employing a blend of public and non-public tools to carry out its cyber espionage activities.

    read more about APT34's Phishing Strategy With New Malware Families Targeting Key Sectors
  11. Public

    Muddyc3: The New Tool Powering MuddyWater's Cyber Espionage Operations

    The MuddyWater APT group carried out a series of spear-phishing attacks between February and April 2019. They targeted government entities, educational institutions, financial, telecommunication, and defense companies in Turkey, Iran, Afghanistan, Iraq, Tajikistan, and Azerbaijan. The group used a tool named muddyc3, capable of delivering a PowerShell payload and managing C&C server communication. Researchers discovered that the tool supports a variety of commands, indicating the use of a command-line interface. It also utilizes character substitution and base64 encoding for obfuscation.

    read more about Muddyc3: The New Tool Powering MuddyWater's Cyber Espionage Operations
  12. Public

    Unveiling TREKX: ITG07's Weapon of Choice for Intrusion in the Transportation Sector

    IBM X-Force researchers documented a sustained intrusion campaign by ITG07 — also tracked as Chafer and APT39 — targeting transportation sector organizations across multiple countries from at least September 2018 through mid-2019. The attackers gained initial footholds by exploiting public-facing applications and deploying webshells (JSPSPY, ASPXSPY), then moved laterally using stolen credentials harvested with a customized version of Mimikatz and legitimate remote access tools including Citrix and PsExec. A previously undocumented custom remote access trojan named TREKX was used to maintain persistent backdoor access. Microsoft BITS was abused for stealthy file transfer and data exfiltration. Internal reconnaissance was conducted using NBTscan. The campaign demonstrated a high level of operational sophistication, combining custom malware with living-off-the-land techniques to avoid detection.

    read more about Unveiling TREKX: ITG07's Weapon of Choice for Intrusion in the Transportation Sector
  13. Public

    MuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

    The MuddyWater threat actor group has resurfaced, launching sophisticated campaigns against targets in the Middle East, Asia and other parts of the world, using new tools like the multi-stage PowerShell backdoor POWERSTATS v3 and various post-exploitation tools. The campaigns involved spear-phishing emails sent from compromised accounts, leading to the deployment of malware designed for intelligence gathering. Targets included a university in Jordan and the Turkish government, highlighting the group's continued focus on geopolitical espionage. The report also discusses MuddyWater's connections to Android malware and the use of false flags to misattribute campaigns, showcasing the group's evolving tactics and infrastructure sophistication.

    read more about MuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East
  14. Public

    A Deep Dive into APT34's Leaked Tool: Analyzing the Jason Project

    Marco Ramilli provides an independent technical analysis of the Jason Exchange Mail BF tool (v7.0), leaked by Lab Dookhtegan on June 3, 2019, as part of the APT34 tool exposure on Telegram. Jason is a graphical .NET tool designed to brute-force Microsoft Exchange accounts and harvest email addresses and account credentials. It was distributed in a ZIP container containing three components: Jason.exe (the GUI frontend), Microsoft.Exchange.WebService.dll (version 15.0.0.0, dated to 2012 despite a last-available 2015 release — suggesting the tool may have been initially developed or frozen around that period), and a password pattern library (PassSample folder with Year.txt, numspecial.txt, num4.txt, num4special.txt, and username/password list files). Three attack modes are selectable: EWS (Exchange Web Services), OAB (Offline Address Book), or both simultaneously; a DNS domain discovery function is also present in the code for auto-detecting Exchange servers. The tool supports configurable thread counts for attack speed tuning. Ramilli notes the developer implemented extensive exception-handling protections — checks for null bytes, variable validation, object index and key guards — which he interprets as either targeting non-technical end users or reflecting professionally-trained development practices. He identifies weak code style similarities with other APT34 tools (Glimpse, WebMask) in exception protection patterns and file logging conventions, but explicitly withholds personal attribution, noting these similarities are insufficient for confident APT34 attribution beyond the trusted source (Lab Dookhtegan). The PDB path (D:\Project\Jason\obj\Release\Jason.pdb) and version string "Jason - Exchange Mail BF - v 7.0" confirm the internal project name. Ramilli publishes a YARA rule (_APT34_Jason) with 20 strings for detection. Source URL is no longer accessible; this analysis is based on the archived PDF attachment.

    read more about A Deep Dive into APT34's Leaked Tool: Analyzing the Jason Project
  15. Public

    MuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns

    The Iranian APT group MuddyWater has expanded its tactics, targeting government, telecommunications and military sectors in countries such as Tajikistan, Pakistan and Iraq. New campaigns include decoy documents exploiting CVE-2017-0199 and malicious VBA macros, with second-stage payloads downloaded from compromised servers. Primary targets have impersonated entities in the region surrounding Iran, including Iraqi and Pakistani organisations. The group also uses RATs for process detection, using obfuscation techniques such as Base64 encoding and JavaScript layers. Compromised servers in Pakistan and China facilitated these operations, demonstrating MuddyWater's sophisticated arsenal and focus on espionage.

    read more about MuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns
  16. Public

    Lab Dookhtegan Exposes APT34's Email Hacking Tool: The Silent Threat of 'Jason'

    Telsy published the first public analysis of Jason on June 3, 2019 — the same day Lab Dookhtegan released it on Telegram — making this the earliest documented response to the leak. Jason is a .NET graphical tool designed to brute-force Exchange email accounts using OAB and EWS methods, with support for user/password lists loaded from text files and configurable multi-threading. The tool was not flagged by any VirusTotal engine at time of analysis; Telsy explicitly notes this and calls on security vendors to classify Jason and similar hacking tools as potentially malicious. Scan results are written to out-[datetime].txt files; debug and activity logs are saved to log.txt. Telsy characterizes the tool as "simple old-style appearing but potentially very effective" and notes that multiple versions appear to have been released over time, with version 7.0 likely dating to early 2019. On June 4, 2019, Telsy published a tlp:white YARA detection rule for Jason on their public GitHub repository (github.com/telsy-cyberops/research/blob/master/APT34/YARA), available for immediate use by defenders.

    read more about Lab Dookhtegan Exposes APT34's Email Hacking Tool: The Silent Threat of 'Jason'
  17. Public

    MuddyWater's BlackWater: An In-depth Look at Advanced TTPs

    The MuddyWater-associated BlackWater campaign has displayed advanced TTPs in its latest activities. Using obfuscated VBA and PowerShell scripts, the threat actors establish persistence via registry keys and utilize multi-staging payloads. The campaign employs an open-source framework, FruityC2, to further enumerate the victim's host machine and evade signature-based detection mechanisms. The actor-controlled servers are used for command and control, making host-based detection challenging. Compared to earlier samples, the new tactics require a multi-step investigative approach.

    read more about MuddyWater's BlackWater: An In-depth Look at Advanced TTPs
  18. Public

    Cyber Espionage Unveiled: APT34's Targeted Attacks on Government and Finance Systems

    APT34 primarily targets Middle Eastern countries and international organizations across finance, government, energy, chemical engineering, and telecommunications sectors. Disclosed by Lab Dookhtegan, APT34 employs various attack methods, including SQL injection, brute-force cracking, and 0-day exploits. The group frequently uses web shells injected into compromised systems to maintain control. Top attacked countries include the United Arab Emirates, China, Jordan, and Saudi Arabia. The compromised enterprises predominantly belong to government (36%), finance (17%), service provider (12%), and media (7%) sectors. APT34's attacks typically begin with exploiting web vulnerabilities to gain initial access.

    read more about Cyber Espionage Unveiled: APT34's Targeted Attacks on Government and Finance Systems
  19. Public

    APT34's Glimpse Project: Sophisticated Cyber Espionage in the Middle East

    Since at least 2014, APT34, has targeted financial, government, energy, chemical, telecommunications, and other industries in the Middle East. Their Glimpse project uses a file-based command and control structure, including a VBS launcher and a PowerShell payload, with covert channels over DNS. Tools leaked on a Telegram channel were linked to OilRig, confirming their use in multiple intrusions across the Middle East and Asia. The attacks include sophisticated PowerShell scripts for command execution and data exfiltration.

    read more about APT34's Glimpse Project: Sophisticated Cyber Espionage in the Middle East
  20. Public

    OilRig's Global Cyber Offensive: Credential Theft and Persistent Access

    The OilRig group has been actively targeting various sectors, including government, media, energy, and technology across 27 countries. The group has stolen nearly 13,000 credentials, deployed over 100 webshells, and maintained backdoor access to compromised hosts. Techniques include credential dumping with Mimikatz, DNS hijacking, and using PowerShell-based tools like Glimpse and Poison Frog. Their operations involve SQL injections, exploiting public-facing applications, and leveraging webshells for persistent access. The group's sophisticated TTPs underline their persistent threat to diverse industry verticals.

    read more about OilRig's Global Cyber Offensive: Credential Theft and Persistent Access
  21. Public

    Decoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics

    The MuddyWater APT group has been actively targeting governmental and telecommunications sectors in the Middle East, including Iraq, Saudi Arabia, Bahrain, Jordan, Turkey, and Lebanon, with additional activities in Azerbaijan, Pakistan, and Afghanistan. This report reveals the group's post-infection strategies, highlighting the deployment of custom-developed tools and scripts in Python, C#, and PowerShell for victim infiltration and data exfiltration. These tools include download/execute utilities, RATs, SSH scripts, and techniques for credential extraction and system information gathering. MuddyWater's deceptive tactics, such as impersonating other hacking groups and embedding misleading code strings, are also noted, aiming to complicate attribution and investigation efforts.

    read more about Decoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics
  22. Public

    APT34’s Webmask Project: DNS Hijacking and Targeted Cyber Attacks

    APT34 has been leveraging DNS tunneling for command and control since May 2016. The leaked source code, revealed via a Telegram channel, includes projects like webmask which primarily focus on DNS hijacking and redirection attacks. The attacks target sectors such as technology firms, telecom companies, and gaming companies across the Middle East and Asia, with a particular focus on UAE. The setup involves using NodeJS and Python for DNS servers, an ICAP proxy server to intercept and modify connections, and Haproxy for high availability.

    read more about APT34’s Webmask Project: DNS Hijacking and Targeted Cyber Attacks
  23. Public

    APT34 Leak Exposes Espionage Tools and Tactics of Iranian Cyber Actors

    The APT34/OILRIG group, linked to Iranian intelligence, had its operational details leaked by the "Lab Dookhtegan" group on Telegram. The leaks revealed a C2 infrastructure, PowerShell-based agents, ASP web shells ("HighShell" and "HyperShell"), and a DNS-based espionage toolset ("dnspionage"). These tools facilitate file transfer, credential theft and covert communication via proxies and DNS manipulation. The attackers also collected sensitive data, including domain admin credentials, indicating a potential target for high-value networks. While specific sectors or countries are not detailed, the tools suggest a focus on espionage and disruption. Other tools, such as 'MinionProject' and 'FoxPanel222', remain under analysis.

    read more about APT34 Leak Exposes Espionage Tools and Tactics of Iranian Cyber Actors
  24. Public

    Analyzing OilRig's Use of DNS Tunneling in Cyber Espionage Campaigns

    The report highlights OilRig’s deployment of tools like Helminth, ISMAgent, ALMACommunicator, BONDUPDATER, and QUADAGENT, which utilize DNS queries to communicate stealthily with C2 servers. This covert communication method is favored due to DNS's typical allowance through security devices. The group has evolved its DNS tunneling protocols over time, using customized subdomains and encoding techniques to transmit data and evade detection effectively.

    read more about Analyzing OilRig's Use of DNS Tunneling in Cyber Espionage Campaigns