Threats Feed
- Public
SamSam Ransomware: Targeted Attacks Disrupt U.S. Healthcare and Government
Symantec's October 2018 analysis documented 67 confirmed SamSam targets during 2018, with 56 located in the United States. Healthcare was the single most affected sector, accounting for 24 percent of attacks, followed by local government organizations — at least one of which was involved in election administration. The group's most high-profile attack hit the City of Atlanta in March 2018, causing cleanup costs estimated at over $10 million; an attack on the Colorado Department of Transportation resulted in an additional $1.5 million in remediation costs. A November 2018 update confirmed that a US DOJ indictment of two Iranian nationals placed total ransom received at $6 million and damages to victims at over $30 million. SamSam operators employed "living off the land" tactics throughout — using legitimate administrative tools including PsExec, PsInfo, and Mimikatz rather than custom malware for reconnaissance, credential theft, and lateral movement. A documented February 2018 attack showed more than 48 hours elapsed between initial intrusion and encryption, during which the attackers mapped the network, harvested credentials, and staged two SamSam variants before encrypting nearly 250 computers in a single five-hour window. Outside the US, a small number of attacks were confirmed in Portugal, France, Australia, Ireland, and Israel.
read more about SamSam Ransomware: Targeted Attacks Disrupt U.S. Healthcare and Government - Public
MuddyWater APT's Spear Phishing Campaigns Target Middle East's Sectors
The MuddyWater APT group has been leveraging spear phishing attacks with malicious Word documents to infiltrate systems in the oil, military, telecom, and government sectors. These documents, often in the native language of the target, entice users to enable macros, leading to a chain of malicious activities. The malware, once activated, employs techniques like modifying registry keys, creating scheduled tasks, and using PowerShell to decode payloads and establish persistence. It cleverly evades detection by disguising its activities under seemingly legitimate processes and alters security settings like disabling firewalls and antivirus. Network analysis revealed beaconing to C2 servers, indicating a sophisticated level of stealth and persistence.
read more about MuddyWater APT's Spear Phishing Campaigns Target Middle East's Sectors - Public
MuddyWater Expands Spear-Phishing Operations across Multiple Countries and Sectors
The MuddyWater group has expanded its cyber operations, focusing mainly on government bodies, military entities, telecommunication companies, and educational institutions. The new spear-phishing docs used by MuddyWater rely on social engineering to persuade users to enable macros, thereby initiating malware extraction and execution. The malware is designed for extensive system reconnaissance, and the command-and-control communication structure allows the threat actors to accept or reject victims based on various criteria.
read more about MuddyWater Expands Spear-Phishing Operations across Multiple Countries and Sectors - Public
OilRig Continues Assault on Middle Eastern Governments and Businesses with BONDUPDATER
The OilRig group has continued its cyber attacks, mainly in the Middle East. The group targeted governmental organizations using spear-phishing emails, delivering an updated Trojan known as BONDUPDATER. The Trojan allows threat actors to upload and download files, execute commands, and uses DNS tunneling for C2 communications. It also employs a new technique of DNS tunneling protocol via DNS TXT records. The continued onslaught of OilRig attacks into 2018 is of concern, with variations of previous tools being reused, capitalizing on their prior success.
read more about OilRig Continues Assault on Middle Eastern Governments and Businesses with BONDUPDATER - Public
Domestic Kitten: Iranian Surveillance on Citizens Using Malicious Mobile Apps
The Domestic Kitten campaign, an Iranian surveillance operation active since 2016, targets Iranian citizens, including Kurdish and Turkish natives and ISIS supporters, using malicious mobile apps. These apps, disguised as legitimate, collect sensitive information such as contact lists, call records, SMS messages, browser history, geo-location, photos, and surrounding voice recordings. The stolen data is encrypted and exfiltrated to C&C servers, with IP addresses linked to Iranian origins. The operation's infrastructure suggests involvement by Iranian government entities like the IRGC and Ministry of Intelligence.
read more about Domestic Kitten: Iranian Surveillance on Citizens Using Malicious Mobile Apps - Public
Time-Zone Specific OopsIE Variant Reinforces OilRig’s Targeted Approach
Palo Alto Unit42 documents an evolved OopsIE variant deployed by OilRig against a Middle Eastern government agency in mid-2018, adding nine anti-analysis and anti-VM checks to an otherwise functionally similar trojan. The spearphishing email used an Arabic subject line ("Business continuity management training") sent to a group email address whose members had publicly published documents on that topic — indicating deliberate target research. The nine evasion checks (executed before any functional code runs) query for: CPU fan presence (Win32_Fan WMI — novel at time of publication), CPU temperature (MSAcpi_ThermalZoneTemperature — also seen in GravityRAT), mouse pointer manufacturer strings (Win32_PointingDevice — checks for VMware/VBox/Oracle), hard disk model strings (Win32_DiskDrive), motherboard manufacturer strings (Win32_BaseBoard), Sandboxie DLL (SbieDll.dll), VBox DLL (vboxmrxnp.dll), VMware DLLs (vmGuestLib.dll / vmbusres.dll), and a time zone check (DaylightName compared against Iran, Arab, Arabia, Middle East — covering UTC+2/+3/+3.5/+4 across 10 countries). A tenth check requires the user to click OK on a fake user32.dll error dialog, ensuring human interaction. Strings are obfuscated using a hyphen-delimited integer encoding (each value minus 1, converted to character). The GUID written to GDI.bin is used as the scheduled task name (replacing the hardcoded name in earlier variants), and the Trojan copies itself to %APPDATA%\Windows\WindowsImplantment.exe with hidden and system flags. C2 communication uses Internet Explorer application object HTTP requests; URL parameter strings are reversed from the previous variant (chk→khc, what→tahw, resp→pser, oops→spoo). A 2-second delay using cmd.exe choice is inserted post-dialog. Four commands are supported: run command (1), download file (2), read/upload file (3), and boom! (uninstall). C2 domain: windowspatch[.]com.
read more about Time-Zone Specific OopsIE Variant Reinforces OilRig’s Targeted Approach - Public
COBALT DICKENS Phishing Campaign Targets Global Universities for Credential Theft
In August 2018, Secureworks researchers uncovered a credential-stealing campaign targeting universities worldwide, likely conducted by the Iranian-linked COBALT DICKENS group. The attackers used spoofed login pages for 76 universities across 14 countries, including the US, UK, Canada, Israel, and Australia. By creating lookalike domains, the group aimed to phish victims and steal credentials, likely to access intellectual property and academic resources. The infrastructure supporting the campaign was actively developed, with many domains registered just before the attacks. The group's tactics mirrored prior operations targeting academic institutions, despite public indictments against members earlier that year.
read more about COBALT DICKENS Phishing Campaign Targets Global Universities for Credential Theft - Public
Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8
The "Prince of Persia" malware campaign, attributed to Iranian origins and active for over a decade, has evolved with its new version, Foudre version 8. Initially reported by Palo Alto Networks, this malware is distributed via a WinRAR SFX archive containing malicious binaries and a politically themed video. The video serves as a distraction while the malware installs itself. Foudre is a remote access tool capable of executing commands remotely, stealing information like keystrokes and process details, and auto-updating. Its latest iteration shows significant code reuse from previous versions and introduces new functionalities. Key features include checking for the presence of certain software like Kaspersky Lab, modifying the system registry for persistence, and using a Domain Generation Algorithm. The campaign's tactics and tools are sophisticated, suggesting a focused intent on espionage or intelligence gathering.
read more about Prince of Persia: Evolution of Iranian Malware Campaign with Foudre V8 - Public
DarkHydrus Exploits Open-Source Tools in Cyberattacks Against Middle Eastern Governments and Academia
Palo Alto Unit42 documents DarkHydrus conducting credential harvesting attacks against government entities and educational institutions in the Middle East using the open-source Phishery tool, with the campaign active from at least September 2017 through June 2018. Phishery performs two functions: it injects a remote template URL into Word documents (using the Office attachedTemplate technique) and hosts a C2 server to capture credentials entered into the authentication dialog box that Microsoft Office automatically presents when attempting to load the remote template. DarkHydrus used three malicious Word documents in this campaign. The September 2017 document displayed an employee survey as the decoy, and the November 2017 document displayed what appeared to be an internal password handover form — suggesting the actor may have had prior access to the organization's internal materials. The June 2018 document was empty after credential theft. In all cases, when the user opened the document, Word displayed a dialog asking them to authenticate to connect to a remote resource. DarkHydrus' C2 domain 0utl00k[.]net was engineered to resemble Microsoft Outlook's legitimate "outlook.com" domain. For the June 2018 attack, the specific subdomain used matched the name of the targeted educational institution — making the dialog appear to be an internal login prompt — significantly increasing the likelihood of credential submission. Unit42 confirmed DarkHydrus used Phishery by recreating the tool's output and matching the remote template path exactly, then successfully capturing test credentials via the same C2 flow. The use of an open-source tool is consistent with DarkHydrus's broader pattern of leveraging freely available offensive tools rather than developing custom malware.
read more about DarkHydrus Exploits Open-Source Tools in Cyberattacks Against Middle Eastern Governments and Academia - Public
DarkHydrus Targets Middle Eastern Government with RogueRobin Payloads
Palo Alto Unit42 introduces DarkHydrus — a previously undisclosed threat group — and documents their July 2018 attack on at least one Middle Eastern government agency using a novel delivery mechanism: malicious Excel Web Query (.iqy) files hidden inside password-protected RAR archives sent via spearphishing. The .iqy file (credential.iqy) contains a single URL pointing to micrrosoft[.]net, which Excel natively fetches on open. The retrieved releasenotes.txt file contains an Excel formula that launches a cmd.exe subprocess to run a PowerShell one-liner, downloading and executing winupdate.ps1 — RogueRobin — from the same server. Both consent dialogs (one for remote data, one for command prompt execution) must be accepted by the user, making social engineering the critical success factor. RogueRobin performs five WMI-based sandbox checks (BIOS version for VBOX/bochs/qemu/virtualbox/vm strings, XEN manufacturer, physical memory <2.9GB, CPU cores ≤1) and enumerates processes for Wireshark and Sysinternals before proceeding. If checks pass, it writes OneDrive.ps1 to %APPDATA% and creates a startup folder shortcut (OneDrive.lnk) for persistence. All C2 communication uses a custom DNS tunneling protocol, testing eight DNS record types (A, AAAA, AC, CNAME, MX, TXT, SRV, SOA) on first run and using the first to receive a response for all subsequent communications. Each DNS query encodes a system ID, job ID, data offset, and base64-encoded data chunk in the subdomain. The eight C2 domains all spoof well-known security vendor brands (Cisco AnyConnect, F5 BIG-IP, Fortiweb, Kaspersky, MikroTik, OWA365, Symantec, Windows Defender). Infrastructure pivoting linked these domains through shared name servers (ns102/ns103.kaspersky[.]host) and revealed overlapping infrastructure with a second DarkHydrus credential harvesting campaign (0utl00k[.]net) and possible Copy Kittens connections (cisc0[.]net, per ClearSky reporting — unconfirmed by Unit42). Unit42 assesses DarkHydrus has been active since at least January 2016 and historically relied on open-source tools (Meterpreter, Cobalt Strike, Empire, Veil, Mimikatz) before pivoting to the custom RogueRobin payload in this campaign.
read more about DarkHydrus Targets Middle Eastern Government with RogueRobin Payloads - Public
Adapting and Evolving: A Look at the OilRig's QUADAGENT-Driven Attacks
The OilRig group continued its espionage activities, primarily within the Middle East. Between May and June 2018, they orchestrated multiple attacks using compromised accounts from a Middle Eastern government agency, targeting a technology services provider and another government entity. The group leveraged a PowerShell backdoor called QUADAGENT and employed spear-phishing tactics, obfuscation using the Invoke-Obfuscation toolkit, and PE files to achieve their objectives. They also used stolen credentials and decoy dialog boxes to reduce suspicion and evade detection.
read more about Adapting and Evolving: A Look at the OilRig's QUADAGENT-Driven Attacks - Public
Leafminer Cyber Espionage Campaign Targets Middle Eastern Governments
Symantec's July 2018 report exposed Leafminer, an Iran-based threat actor active since at least early 2017, targeting government organizations and multiple business sectors across the Middle East — including Saudi Arabia, the UAE, Qatar, Kuwait, Bahrain, Egypt, Israel, and Afghanistan. Symantec identified a critical operational security failure: Leafminer left a staging server publicly accessible, exposing their entire toolkit of 112 files including custom malware, exploitation frameworks, and reconnaissance logs. The group used three main intrusion methods: watering hole attacks that planted JavaScript to harvest SMB/NTLM credential hashes from visitors' browsers; vulnerability scanning and exploitation using the EternalBlue exploit (CVE-2017-0144/MS17-010) from the leaked Fuzzbunch framework for lateral movement; and dictionary/brute-force attacks against Exchange and RDP logins using THC Hydra and Total SMB BruteForcer. Custom malware included Backdoor.Sorgu (remote access) and Trojan.Imecab (persistent guest account creation). For credential dumping, the group deployed OrangeTeghal — a rebranded Mimikatz — using Process Doppelgänging to evade detection. Post-compromise tools included MailSniper, LaZagne, PsExec, HoboCopy, and SQL backup recovery utilities. Leafminer also scanned for Heartbleed (CVE-2014-0160). A target list written in Farsi containing 809 organizations was recovered from the staging server, grouping targets by geography and industry sector.
read more about Leafminer Cyber Espionage Campaign Targets Middle Eastern Governments - Public
Iranian APT Charming Kitten Mimics ClearSky in Phishing Scheme
The Iranian APT group Charming Kitten impersonated Israeli cybersecurity firm ClearSky by creating a phishing website that mimicked the legitimate Clearskysec.com domain. The fake site, hosted on an older compromised server, replicated ClearSky's public web pages and included phishing login options to harvest credentials. ClearSky identified the incomplete site, which was taken down before it could affect any victims. Charming Kitten has previously targeted academic researchers, human rights activists, media outlets and political consultants in Iran, the US, UK and Israel. Known for spear-phishing, impersonating organisations, and deploying malware such as DownPaper, this campaign underscores the ongoing threat to security researchers and geopolitical targets.
read more about Iranian APT Charming Kitten Mimics ClearSky in Phishing Scheme - Public
Unveiling APT33’s Dropshot: Decrypting the Sophisticated Wiper Malware
APT33’s Dropshot, also known as StoneDrill, is a sophisticated wiper malware targeting organizations primarily in Saudi Arabia. Dropshot uses advanced anti-emulation techniques and obfuscation to evade detection. The malware decrypts its payload from an encrypted resource and employs anti-emulation strategies, including invalid Windows API calls. It also leverages zlib for decompression. This analysis focuses on decrypting Dropshot's encrypted resource to understand its functionality. The malware's association with APT33 and similarities to the Shamoon malware underscore its threat to targeted sectors.
read more about Unveiling APT33’s Dropshot: Decrypting the Sophisticated Wiper Malware - Public
Evolving MuddyWater Campaign Uncovered with PRB-Backdoor Payload
A potential MuddyWater campaign has been discovered using a new sample found in May 2018. The campaign involves a malicious Microsoft Word document with an embedded macro capable of executing PowerShell scripts, leading to a PRB-Backdoor payload. Notably, the lure document's subject matter has changed from government or telecommunications-related documents to rewards or promotions, suggesting that targets may no longer be limited to specific industries or organizations. The backdoor communicates with a C&C server to perform various functions, such as gathering system information, keylogging, and capturing screenshots.
read more about Evolving MuddyWater Campaign Uncovered with PRB-Backdoor Payload - Public
APT33's Dropshot Malware: Advanced Evasion Techniques Unveiled
APT33's Dropshot malware, also known as StoneDrill, targeted organizations primarily in Saudi Arabia. Dropshot, a sophisticated wiper malware, employs advanced anti-emulation techniques and string encryption to evade detection and analysis. The malware's high entropy suggests packed or compressed data, particularly in the .rsrc section, indicating hidden malicious content. This analysis focuses on decrypting the strings within Dropshot.
read more about APT33's Dropshot Malware: Advanced Evasion Techniques Unveiled - Public
PRB-Backdoor: MuddyWater's Multifaceted Malware Uncovered
This report investigates the PRB-Backdoor, a powerful and multifunctional piece of malware suspected to be associated with the MuddyWater group. The malware is deployed via a macro-enabled Word document, utilizing PowerShell scripts for execution. It employs obfuscation techniques to conceal its activities and communicates with a command and control server over HTTP. The backdoor has a plethora of functionalities, including keylogging, screen capturing, system information collection, and password theft. The backdoor seems to be new and unique, with no references found in any public source.
read more about PRB-Backdoor: MuddyWater's Multifaceted Malware Uncovered - Public
Cyber Espionage Evolution: MuddyWater’s Obfuscation Techniques and Anti-Analysis Measures
The MuddyWater or Temp.Zagros group has resumed its activities after a perceived quiet phase, with recent samples revealing additional obfuscation layers. The group continues to use PowerShell, targeting regions such as Turkey, Iraq, and Pakistan, with a potential focus on governmental sectors. The recent malicious documents include a new variant of the POWERSTATS backdoor, with anti-analysis and debugging features such as BSOD functionality. They have also included checks for security software and process names to impair defensive measures.
read more about Cyber Espionage Evolution: MuddyWater’s Obfuscation Techniques and Anti-Analysis Measures - Public
Hospitals and Schools Under Siege: SamSam’s Targeted Ransomware Campaign
SamSam ransomware selectively targets organizations likely to pay ransom, such as hospitals and schools. Unlike indiscriminate ransomware campaigns, attackers exploit vulnerabilities or use brute-force attacks on weak RDP credentials to gain initial access. After infection, SamSam spreads laterally by network mapping and credential theft, deploying ransomware manually via PSEXEC and batch scripts. The malware executes through a runner component, decrypting the payload using a separate DLL. Attackers erase forensic traces by deleting execution-related files. Victims can pay per host or a total sum for decryption. SamSam has generated significant profits in Bitcoin payments, shifting wallet addresses over time to evade tracking.
read more about Hospitals and Schools Under Siege: SamSam’s Targeted Ransomware Campaign - Public
Silent Librarian: Iranian Group Targets Global Universities and Research Institutions
Silent Librarian, an Iranian group tied to the Mabna Institute, has been conducting credential-phishing campaigns targeting over 300 universities and institutions worldwide since 2013. These campaigns focus on prominent research, medical, and technical universities, mainly in the US, UK, Canada, and Australia, as well as non-academic institutions like Los Alamos National Laboratory. Using spoofed emails, Freenom domains, and Let's Encrypt SSL certificates, the group collected credentials to access valuable research data. PhishLabs identified over 750 attacks and 127 phishing domains. The attackers leveraged infrastructure such as temporary email accounts and domain registrations to execute their campaigns.
read more about Silent Librarian: Iranian Group Targets Global Universities and Research Institutions - Public
Multi-Stage Spear Phishing Attack Traced to Iran: TEMP.Zagros in Action
The Iran-affiliated threat actor, TEMP.Zagros, orchestrated a spear-phishing campaign from January to March 2018, primarily targeting individuals across Turkey, Pakistan, Tajikistan, and India. This actor leveraged malicious macro-based documents with geopolitical themes to install the POWERSTATS backdoor on victims' systems. The campaign exhibited evolving tactics over time, employing both VBS files and INF/SCT files to indirectly execute PowerShell commands. The installed malware demonstrated a range of functionalities, from system data extraction and screenshot capture to checks for security tools and remote command execution.
read more about Multi-Stage Spear Phishing Attack Traced to Iran: TEMP.Zagros in Action - Public
MuddyWater Resurfaces: Cyber Attacks Target Turkey, Pakistan, and Tajikistan
A new cyber-espionage campaign, bearing similarities to the earlier MuddyWater attacks, is targeting government organizations and telecommunication companies in Turkey, Pakistan, and Tajikistan. The campaign uses spear-phishing tactics with malicious documents, leveraging social engineering to trick victims into enabling macros and activating payloads. Visual Basic and PowerShell scripts are used, with obfuscation techniques employed to evade detection. The attackers also use persistence methods and engage in system owner/user discovery, collecting system information and taking screenshots before sending this data to a command-and-control server.
read more about MuddyWater Resurfaces: Cyber Attacks Target Turkey, Pakistan, and Tajikistan - Public
Chafer's Rising Ambitions: New Tools and Tactics in the Cyber Threat Landscape
The Iran-based attack group, Chafer, escalated operations in 2017, striking more organizations within and beyond the Middle East. Utilizing several new tools, they targeted sectors including airlines, telecoms services, and IT services for transport sectors among others. Chafer sought to infiltrate a major telecoms services provider and an international travel reservations firm, likely aiming for widespread surveillance. The group employed malicious documents, SQL injection attacks, and newly adopted open-source tools to compromise targets. These activities indicate a growing threat, especially as Chafer shows a rising trend in attacks on supply chains.
read more about Chafer's Rising Ambitions: New Tools and Tactics in the Cyber Threat Landscape - Public
Decoding OilRig's New Cyberthreat: How OopsIE Trojan Targeted Middle East Organizations
The OilRig threat group initiated an attack targeting organizations in the Middle East through spear-phishing emails with a malicious Microsoft Word document called ThreeDollars. The document contained a new payload, OopsIE Trojan, which was delivered either directly or through the document. OilRig implemented different delivery tactics due to prior encounters with their targeted organization. They also adopted password-protected documents as an evasion tactic. The OopsIE Trojan communicated with a C2 server and executed commands provided by it.
read more about Decoding OilRig's New Cyberthreat: How OopsIE Trojan Targeted Middle East Organizations