Latest Update27/08/2026

Threats Feed

  1. Public

    MuddyWater APT Targets Kurdish Political Groups and Turkish Defense Sector

    The Iranian APT group, MuddyWater, targeted Kurdish political groups and Turkish defense sector organizations using emails with malicious Word documents. The documents contained embedded Macros that used PowerShell to execute various commands and modify registry values for persistence. The Macro also used obfuscation techniques, encoding data within image files and a document. The attackers tested their malicious documents against various anti-virus engines, uploading files from Germany and Iraq. This campaign signifies an evolution in MuddyWater's attack methods, with malware extraction now performed locally rather than via a C2 server.

    read more about MuddyWater APT Targets Kurdish Political Groups and Turkish Defense Sector
  2. Public

    Advanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine

    The Iranian APT group MuddyWater has launched a new campaign targeting Belarus, Turkey, and Ukraine. Employing spearphishing as their primary infection vector, the attackers use socially engineered malicious documents to initiate a mainly fileless infection chain. These documents ultimately deliver POWERSTATS, a signature PowerShell backdoor capable of file exfiltration, script execution, and other malicious actions. The recent campaign also introduces a second-stage executable not written in PowerShell, which is packed with UPX and employs anti-analysis techniques. The executable gathers system information and communicates with a C&C server.

    read more about Advanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine
  3. Public

    The Elfin Threat: Customized Malware Attacks Across Diverse Sectors

    Symantec's March 2019 report documents the sustained espionage operations of Elfin (also tracked as APT33), an Iranian-linked group active since late 2015. Over three years, Elfin compromised at least 50 organizations across Saudi Arabia, the United States, and multiple other countries, targeting sectors including research, chemical, engineering, manufacturing, finance, telecommunications, energy, IT, and healthcare. The group routinely scans for vulnerable public-facing websites to identify targets and build command-and-control infrastructure. Its arsenal spans custom malware (TURNEDUP/Notestuk, StoneDrill, AutoIt backdoor), commodity RATs (Remcos, DarkComet, Quasar, Pupy, NanoCore, NetWeird), and open-source post-exploitation tools (Mimikatz, LaZagne, PoshC2, Empire). A documented February 2019 intrusion into a U.S. organization shows the full attack chain: a spearphishing link delivered via email, PowerShell-based staging, scheduled task persistence, credential dumping, and data exfiltration over FTP using a custom tool called FastUploader. The report also notes a February 2019 attempted exploitation of CVE-2018-20250 (WinRAR) against a Saudi chemical-sector target.

    read more about The Elfin Threat: Customized Malware Attacks Across Diverse Sectors
  4. Public

    The Invisible Threat: Chafer's Advanced Backdoor Malware Analysis

    The report provides a comprehensive analysis of a 64-bit backdoor executable associated with the Chafer APT group. The malware utilizes complex features such as process injection, task scheduling, and data obfuscation, along with automated exfiltration of information. It communicates with its C2 server via POST requests and employs encryption algorithms like RC4 and Blowfish to conceal its data and operations. Unusually, it masquerades by creating CAB files with non-standard prefixes and encrypting data in a manner that appears like a routine system operation.

    read more about The Invisible Threat: Chafer's Advanced Backdoor Malware Analysis
  5. Public

    MuddyWater Cyber Campaign Expands to Target Korek Telecom in Iraq

    The MuddyWater APT group is suspected of targeting Korek Telecom, a leading mobile operator in Iraq, through a sophisticated spear phishing campaign. The attack involved sending emails with malicious Office Word documents, urging victims to enable macros, which then executed a PowerShell backdoor. This approach enabled remote control of the victim's computer. The backdoor, known as POWERSTATS, was heavily obfuscated and facilitated data exfiltration and command execution via a C2 server. The group, traced back to early 2017, has expanded their attacks beyond Iran and Saudi Arabia to target government agencies, communication, oil companies, and educational institutions across Asia, Europe, and Africa.

    read more about MuddyWater Cyber Campaign Expands to Target Korek Telecom in Iraq
  6. Public

    Unraveling MechaFlounder: Chafer's New Python-Based Tool Targets Turkey

    In November 2018, the Iranian-linked Chafer threat group deployed a previously unseen Python-based backdoor called MechaFlounder against a Turkish government entity — marking the first confirmed use of a Python payload by this actor. The malware was compiled into a standalone executable using PyInstaller, allowing it to run on target systems without requiring a Python interpreter and making it harder to identify through file-type signatures alone. It was delivered from a malicious domain directly tied to prior Chafer infrastructure, indicating deliberate reuse of established operational resources. MechaFlounder functions as a fully capable remote access tool, supporting file upload and download, command execution, and C2 communication over HTTP using Base64-encoded data. Palo Alto Networks analysts noted that portions of MechaFlounder's code overlap with tooling associated with OilRig, a separate Iranian-linked threat group, suggesting a degree of code sharing or shared development resources between the two actors.

    read more about Unraveling MechaFlounder: Chafer's New Python-Based Tool Targets Turkey
  7. Public

    SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants

    The provided report outlines the activities of a malware campaign leveraging the SeedWorm backdoor, specifically through variants of a program named LisfonService. These variants were developed and deployed using PowerShell to download and execute a malicious program, 'muddy', across targeted systems. Notably, the campaign utilizes filenames such as svchosts.exe and lisfon.exe to obscure its malicious intent.

    read more about SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants
  8. Public

    Chafer APT Targets Iranian Diplomatic Entities with Updated Remexi Malware

    Throughout autumn 2018, Kaspersky researchers identified an active cyber-espionage campaign attributed to the Iran-based Chafer group, targeting foreign diplomatic entities operating inside Iran. The attackers deployed an updated version of Backdoor.Remexi — a Windows trojan capable of logging keystrokes, capturing screenshots, stealing browser credentials and history, and executing remote commands. The malware relied heavily on Microsoft's Background Intelligent Transfer Service (BITS) for both receiving commands and exfiltrating collected data, blending malicious traffic with legitimate Windows activity. Persistence was maintained through scheduled tasks and registry modifications. Encryption used XOR and RC4 algorithms with unique per-sample keys; one sample used the Farsi word for "health" as a key, reinforcing Iranian attribution. Kaspersky assessed the campaign as a likely domestic counter-intelligence operation.

    read more about Chafer APT Targets Iranian Diplomatic Entities with Updated Remexi Malware
  9. Public

    Unmasking APT39: Cyber Attacks on a Global Scale with Focus on the Middle East

    APT39 is a cyber espionage group known for widespread theft of personal information, predominantly from the telecommunications and travel sectors. The group's operations are globally targeted but primarily concentrated in the Middle East. They involve monitoring, tracking, and conducting surveillance of specific individuals. The techniques used by APT39 include spear phishing, exploiting vulnerable web servers, and credential theft. Furthermore, APT39 deploys backdoors and uses various tools for privilege escalation, reconnaissance, lateral movement, and data extraction.

    read more about Unmasking APT39: Cyber Attacks on a Global Scale with Focus on the Middle East
  10. Public

    Widespread DNS Hijacking Campaign with Possible Iranian Nexus Targets Multiple Sectors

    CrowdStrike Intelligence's January 2019 report documents a widespread DNS hijacking campaign active from at least February 2017 through January 2019, affecting 28 organizations across 12 countries. The campaign primarily targeted entities in the Middle East and North Africa, with limited impact in Europe and the United States. Affected sectors included government (the dominant target across Jordan, Kuwait, UAE, Iraq, Egypt, Libya, Lebanon, Albania, Cyprus, and Saudi Arabia), law enforcement, civil aviation, insurance, telecommunications, and internet infrastructure providers including ISPs, internet exchange points, root DNS servers, and TLD operators. The attack method involved hijacking victim organizations' DNS records to redirect traffic to actor-controlled IP addresses. Fraudulent TLS certificates were then obtained — primarily through Let's Encrypt — enabling the actors to present trusted HTTPS connections to victims redirected to malicious infrastructure. Most hijacked domains remained redirected for very short windows (sometimes under 24 hours), though one domain was hijacked for over a month. Five actor-controlled name server domains were used as malicious authoritative DNS: cloudipnameserver.com, cloudnamedns.com, lcjcomputing.com, mmfasi.com, and interaland.com. CrowdStrike assessed that the likely objectives were direct traffic interception, credential collection, and potential malware delivery against targeted organizations. Public reporting at the time pointed to a possible Iranian nexus, though CrowdStrike stated definitive attribution was inconclusive at the time of publication.

    read more about Widespread DNS Hijacking Campaign with Possible Iranian Nexus Targets Multiple Sectors
  11. Public

    DarkHydrus Resurfaces with New Trojan Leveraging Google Drive for C2 Activities

    DarkHydrus, an adversary group operating primarily in the Middle East, has resumed activities with new tactics, tools, and procedures (TTPs). Recently analyzed by security researchers, the group has been deploying a new variant of the RogueRobin trojan, which now utilizes Google Drive API for command and control (C2) communications. This shift to using legitimate cloud services for C2 indicates an evolution in their operational tactics. The trojan, delivered through macro-enabled Excel documents, exhibits sophisticated evasion techniques, including environment checks and dynamic DNS to mask its C2 communications. The analysis revealed the use of typosquatting and open-source penetration testing tools, underscoring the group’s persistent and evolving threat landscape.

    read more about DarkHydrus Resurfaces with New Trojan Leveraging Google Drive for C2 Activities
  12. Public

    DNSPIONAGE: Unpacking Advanced Spear Phishing and Lateral Movement Techniques

    CERT-OPMD (Openminded) published a detailed incident response analysis of a live DNSpionage intrusion in January 2019, focusing on post-compromise internal actions not visible to Cisco Talos from their telemetry. The attackers conducted advanced LinkedIn-based spearphishing, impersonating a Wipro HR recruiter for several days before delivering a malicious document (using the hr-wipro[.]com and hr-suncor[.]com domains observed by Talos). After initial compromise via the DNSpionage backdoor, attackers used batch scripts to perform full recursive directory listings across all drives and exfiltrated results via HTTP to the C2 at 0ffice36o[.]com. They conducted extensive discovery using native Windows tools including WMIC, net, ping, ipconfig, and reg query, identified domain admins, and scanned for antivirus. Credential dumping was performed via Mimikatz (sekurlsa::logonpasswords) invoked through PowerShell with execution bypass. Lateral movement used Plink (plink32.exe) to create SSH tunnels on port 443 to attacker-controlled IP 185.236.78.63, enabling RDP access to internal servers. Files including PowerShell scripts and tools were copied via Windows Admin Shares (net use). The C2 communicated over both HTTP (port 80) and DNS (Base32-encoded queries to 0ffice36o[.]com subdomains), with the malware switching between modes. Openminded confirmed Bitvise WinSSHD was installed for remote access, and Veil-Pillage was used alongside Mimikatz for credential operations.

    read more about DNSPIONAGE: Unpacking Advanced Spear Phishing and Lateral Movement Techniques
  13. Public

    DNS Hijacking Campaign with Suspected Iranian Links Targets Global Domains

    Mandiant's January 2019 report was the first public disclosure of a large-scale DNS hijacking campaign affecting domains across the Middle East and North Africa, Europe, and North America from January 2017 to January 2019. The attackers manipulated both DNS A records (changing the IP address a domain resolves to) and NS records (changing the authoritative name server for a domain), redirecting victim traffic through attacker-controlled infrastructure. SSL certificates were obtained for the hijacked domains to prevent browser warnings and make the interception transparent to victims. Credentials were harvested from the intercepted traffic. Targeted sectors included government, telecommunications, internet infrastructure providers, and other organizations across the MENA region. Mandiant noted that some techniques observed were previously associated with Iranian cyber espionage activity, leading to the assessment of a suspected Iranian nexus — though definitive attribution was not established. The campaign operated in waves, with multiple hijacking operations conducted at different times targeting organizations in different countries. Mandiant's analysis was published shortly before CrowdStrike's complementary report, prompting coordinated government-level advisories from CISA and other agencies urging immediate DNS record monitoring and registrar account security hardening.

    read more about DNS Hijacking Campaign with Suspected Iranian Links Targets Global Domains
  14. Public

    APT33 Targets Engineering Sector: A Blend of Public Tools and Custom Malware

    Mandiant's Managed Defense documented a series of contained intrusions against engineering sector organizations from November 2017 through December 2018, assessed with low-to-medium confidence as APT33 activity. The actor consistently exploited Microsoft Exchange and Outlook using stolen credentials and SensePost's RULER tool — first via malicious client-side mail rules delivering an AutoIT downloader over WebDAV (November 2017), then via CVE-2017-11774 (RULER.HOMEPAGE) to modify Outlook client homepages for persistent code execution (July–August 2018). The initial AutoIT downloader retrieved PowerSploit and reflectively loaded PUPYRAT. In later stages the actor transitioned to PoshC2 .NET stagers — configured with kill dates and AES-encrypted Base64 C2 traffic — then further escalated to POWERTON, a custom multi-layer obfuscated PowerShell backdoor supporting WMI and registry Run key persistence, HTTP(S) C2 over AES, and (in v2) credential dumping. Privilege escalation used CVE-2017-0213; credential theft used Procdump against LSASS and Mimikatz. After Managed Defense contained one intrusion, the actor reestablished access via password spraying within three weeks. Mandiant noted strong circumstantial overlap with confirmed APT33 tooling timelines and assessed the activity posed a heightened risk to critical infrastructure, particularly the energy sector. A July 2019 update confirmed full attribution to APT33 operating on behalf of the Iranian government.

    read more about APT33 Targets Engineering Sector: A Blend of Public Tools and Custom Malware
  15. Public

    APT33 Suspected in Latest Shamoon Attacks Targeting Middle East and European Energy Sector

    McAfee Advanced Threat Research analysts attribute a late-2018 wave of Shamoon destructive attacks to APT33, or a group impersonating them. The campaign used a modular .NET toolkit — comprising OCLC.exe, spreader.exe, SpreaderPsexec.exe, and a new file-erasure wiper called Filerase — alongside Shamoon Version 3. Initial access was gained through spear-phishing websites that mimicked legitimate energy-sector job portals, harvesting corporate credentials from targeted organizations in the Middle East and Europe as early as August 2018. Attackers then used those credentials to move laterally and deploy wipers across victim networks in a supply-chain-style operation, with the wiper execution stage reached in December 2018.

    read more about APT33 Suspected in Latest Shamoon Attacks Targeting Middle East and European Energy Sector
  16. Public

    Beyond Disttrack: Unraveling Shamoon 3's Complex Wiper Malware Campaign

    Unit 42's continued investigation into the Shamoon 3 attacks on an oil and gas organization revealed a new wiper Trojan related to the Disttrack malware, utilizing the SuperDelete tool's modified source code. Unlike previous variants, this wiper doesn't spread across networks but overwrites files with random data, complicating recovery. Notably, it carries a religious message, discovered only upon in-depth analysis. Further analysis identified Loader and Spreader Trojans, indicating a sophisticated approach to distribute the wiper across compromised networks, echoing tactics from Shamoon 2.

    read more about Beyond Disttrack: Unraveling Shamoon 3's Complex Wiper Malware Campaign
  17. Public

    Shamoon's Latest Version: A Growing Threat to the Middle East and European Industries

    McAfee Advanced Threat Research identified a new Shamoon Version 3 variant in December 2018, first detected when the Foundstone Emergency Incident Response team reacted to a customer breach. The variant targeted oil, gas, energy, telecom, and government organizations across the Middle East and southern Europe. Shamoon V3 operates as a modular dropper carrying three embedded components: a communication module (MNU), a wiper (LNG), and a 64-bit dropper (PIC). The wiper installs a malicious service named MaintenaceSrv and uses the ElRawDisk.sys driver to overwrite all files with garbage data before forcing a system reboot, leaving machines inoperable. The malware includes anti-forensic timestomping (faking file dates to August 2012), UAC bypass via token impersonation, and spreads laterally over ADMIN$ and Windows admin shares. The modular design means the wiper component can be detached and weaponized independently, making this variant particularly dangerous for future repurposing.

    read more about Shamoon's Latest Version: A Growing Threat to the Middle East and European Industries
  18. Public

    Seedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors

    Seedworm has compromised more than 130 victims across 30 organizations since September 2018. The group targets primarily the Middle East, Europe, and North America, focusing on government agencies, oil and gas companies, NGOs, telecoms, and IT firms. Seedworm uses tools such as Powermud, Powemuddy, and PowerShell scripts and has updated its tactics to avoid detection. The main targeted sectors include telecommunications, IT services, oil and gas, universities, and embassies. The group is known for its speed and agility in obtaining actionable intelligence from targeted organizations.

    read more about Seedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors
  19. Public

    Spear-Phishing and POWERSTAT: Dissecting MuddyWater's Latest Middle East Attacks

    In late November 2018, the Iranian APT group MuddyWater launched a new series of attacks in Middle East countries, targeting Lebanon, Oman, and Turkey. The campaign, consistent with their previous tactics since 2017, utilized spear-phishing emails with blurred documents to trick victims into enabling VB-macro code, subsequently infecting hosts with POWERSTAT malware. The attack involved creating a malicious Excel document for downloading further payloads, using PowerShell and JavaScript for execution delays, and establishing persistence through registry modifications and scheduled tasks. The POWERSTAT backdoor facilitated data exfiltration and remote command execution, highlighting MuddyWater's continued reliance on scripting languages and system tools for their objectives.

    read more about Spear-Phishing and POWERSTAT: Dissecting MuddyWater's Latest Middle East Attacks
  20. Public

    SamSam Ransomware Targets US Critical Infrastructure with RDP Exploits

    The SamSam ransomware group exploited vulnerabilities in Windows servers and JBoss applications, predominantly targeting organizations in the United States, with victims also reported internationally. The group focused on critical infrastructure sectors and other industries, leveraging stolen Remote Desktop Protocol (RDP) credentials obtained from darknet marketplaces. Using brute force and exploitation techniques, SamSam actors gained persistent access, escalated privileges, deployed ransomware, and encrypted entire networks to demand Bitcoin ransoms. Victims received instructions via Tor for ransom payment and decryption. The rapid execution of attacks and the sale of stolen credentials often resulted in additional unauthorized activities on victim networks.

    read more about SamSam Ransomware Targets US Critical Infrastructure with RDP Exploits
  21. Public

    MuddyWater Expands Cyberattacks with Two-Stage Spear-phishing Campaign Targeting Lebanon and Oman

    The MuddyWater threat group has been launching two-stage spear-phishing attacks on targets in Lebanon and Oman. The first stage involves sending macro-embedded documents posing as resumes or official letters. These documents contain obfuscated code hosted on compromised domains. In the second stage, obfuscated source code from these domains is executed to propagate MuddyWater's main PowerShell backdoor, POWERSTATS. This campaign marks a shift from single-stage to two-stage attacks, allowing for stealthier delivery of the payload.

    read more about MuddyWater Expands Cyberattacks with Two-Stage Spear-phishing Campaign Targeting Lebanon and Oman
  22. Public

    HELIX KITTEN: Expanding Cyber Threat to Telecommunications and Middle Eastern Targets

    The adversary group, HELIX KITTEN, is employing spear-phishing attacks and using custom PowerShell implants (Helminth and ISMDoor) to target entities in the aerospace, energy, financial, government, hospitality, and telecommunications sectors. With a special focus on the Middle East, specifically Bahrain and Kuwait, the group manipulates DNS AAAA records for command and control, and exfiltrates data, captures screenshots, and executes arbitrary commands on victims' machines. Furthermore, HELIX KITTEN has begun targeting the telecommunications industry, possibly for bulk data collection and rerouting communications for future intelligence activities.

    read more about HELIX KITTEN: Expanding Cyber Threat to Telecommunications and Middle Eastern Targets
  23. Public

    DNSpionage Campaign Targets Lebanon and UAE Government Domains

    Cisco Talos discovered a targeted campaign in November 2018 affecting government domains in Lebanon and the UAE, as well as Middle East Airlines. The attackers operated on two tracks simultaneously. First, they delivered a custom backdoor called DNSpionage via malicious Word documents hosted on fake job listing websites (hr-wipro[.]com and hr-suncor[.]com), which used embedded macros to drop and execute a remote administration tool supporting both HTTP and DNS command-and-control. The malware stored commands in a fake Wikipedia page, used a custom per-target Base64 alphabet for obfuscation, and communicated over DNS by encoding data as Base32-encoded subdomain queries to 0ffice36o[.]com. Second, the same actor conducted parallel DNS redirection attacks against specific government and airline hostnames in Lebanon and the UAE between September and November 2018 — redirecting email and VPN domains to attacker-controlled IP 185.20.187.8 after pre-generating matching Let's Encrypt certificates, enabling silent interception of credentials and potentially MFA codes. Named redirected domains included the Lebanese Finance Ministry's webmail, Abu Dhabi Police VPN, UAE Ministry of Government Services mail, UAE Telecommunications Regulatory Authority mail, and multiple Middle East Airlines domains. Talos assessed both activities originated from the same actor and confirmed victims in Lebanon and the UAE via DNS telemetry data. No attribution to a specific group was established.

    read more about DNSpionage Campaign Targets Lebanon and UAE Government Domains
  24. Public

    Uncovering OilRig’s Malware Testing Ops for Targeted Attacks in the Middle East

    Palo Alto Unit42 provides unique insight into OilRig's pre-attack operational tempo by reconstructing a 6-day testing timeline that preceded the August 26, 2018 BONDUPDATER attack on a Middle Eastern government. By analyzing 11 test Excel documents submitted to public VirusTotal-style scanning services between August 20–26, Unit42 mapped every iterative macro change the attacker made to lower AV detection rates — from 22 detections on the first submission down to 7 on the last, with a rebound to 38 on the final weaponized Word document (N56.15.doc). The test files were named XLS-withyourface.xls and sss.xls, with the C2 domain (withyourface[.]com) embedded directly in the early filenames, linking them conclusively to the BONDUPDATER attack. The tester averaged 33 seconds between file save and VirusTotal submission, conducted three testing waves, and pivoted from Excel to Word for the final delivery document. Key technical lessons the attacker applied: removing the "powershell.exe" string from VBScript lowered detections from 22 to 16; removing the wscript execution call dropped detections from 16 to 6; using vbHide (hidden window) flag caused 8 additional detections compared to vbNormalFocus (visible window); and hex-character concatenation obfuscation of "powershell", "cmd.exe", and "wscript" strings bypassed most detections. The final weaponized Word document was created less than 8 hours after the last test iteration and delivered via spearphishing 20 minutes after its creation, setting a precise operational tempo. OilRig also added a 10-second sleep using Application.Wait during some testing iterations as an anti-sandbox technique, though this was removed in the final payload.

    read more about Uncovering OilRig’s Malware Testing Ops for Targeted Attacks in the Middle East