Threats Feed
- Public
APT34's Enhanced Cyber Espionage: BONDUPDATER and POWRUNER Malware Variants Unveiled
Booz Allen DarkLabs' Threat Hunt team pivoted from FireEye's December 2017 APT34 report to discover three previously unreported BONDUPDATER/POWRUNER variants, then extended that work using a ClearSky tip to find two more, yielding seven total malware samples linked to APT34 operations. All variants follow the same execution chain: a dropper (.exe) creates and runs rUpdateChecker.ps1 in a staging directory (C:\ProgramData\Windows\Microsoft\java\ or C:\Users\Public\Java), which creates a VBScript and a scheduled task to run the script every minute. The VBScript deploys POWRUNER — a PowerShell backdoor for arbitrary command execution and TCP-based data exfiltration — and in most variants also BONDUPDATER, a downloader that uses a domain generation algorithm (DGA) for DNS-based C2. The DGA for poison-frog[.]club variants generates subdomains from a unique victim ID (derived from MAC address or whoami), randomly inserted parameters, random hex characters, and hardcoded string elements — producing distinct send and receive subdomain formats. A second cluster, identified from a ClearSky tip, uses window5[.]win as the C2 domain with a URI of /update.aspx. Infrastructure pivoting confirmed that poison-frog[.]club, proxycheker[.]pro, and associated IPs (82.102.14.219, 94.23.172.164, 185.15.247.147) overlap with domains mentioned in the original FireEye report (dns-update[.]club, hpserver[.]online, anyportals[.]com), corroborating the APT34 attribution. Booz Allen also provides a YARA rule for static detection of the dropper binaries based on PDB path strings.
read more about APT34's Enhanced Cyber Espionage: BONDUPDATER and POWRUNER Malware Variants Unveiled - Public
Espionage Operations by Flying Kitten Impact US, Israel, and Academia
The Flying Kitten group conducted extensive espionage and surveillance campaigns from 2013 to 2014. Utilizing spearphishing, social engineering, and the "Stealer" malware, they targeted high-profile individuals, security researchers, and various sectors. The campaigns involved compromised social media accounts and phishing domains to gather credentials and sensitive information. The malware recorded keystrokes, took screenshots, and collected system data, focusing on credential harvesting rather than file exfiltration. This activity impacted targets in the United States, Israel, and global academia and business sectors.
read more about Espionage Operations by Flying Kitten Impact US, Israel, and Academia - Public
TwoFace Webshell to RGDoor: A Resilient Cyber Attack on Middle Eastern Organizations
OilRig was identified by Unit 42 as deploying a secondary backdoor, RGDoor, via the TwoFace webshell to regain access to compromised webservers once TwoFace was detected and removed. Targeting eight Middle Eastern government organizations, a financial institution, and an educational institution, RGDoor allows OilRig to execute commands and upload and download files from the server. The backdoor was created using C++, resulting in a DLL that relies on HTTP POST requests to communicate with the backdoor.
read more about TwoFace Webshell to RGDoor: A Resilient Cyber Attack on Middle Eastern Organizations - Public
SamSam Ransomware Evolves, Nets Over $325K in Four Weeks
A new variant of the SamSam ransomware has netted over $325,000 in four weeks, targeting government, healthcare, and industrial control systems (ICS). The attacks are opportunistic, with potential initial access through compromised RDP/VNC servers. The ransomware is deployed manually, encrypting files using DES and AES encryption. New anti-analysis techniques, including string obfuscation and a loader-based deployment mechanism ("Runner"), make detection more challenging. Unlike most ransomware, SamSam does not delete Volume Shadow Copies, allowing possible file recovery. The campaign uses hardcoded Tor addresses and Bitcoin wallets for ransom transactions, with payments being tracked on the blockchain. The US and other regions are likely affected, given past SamSam activity.
read more about SamSam Ransomware Evolves, Nets Over $325K in Four Weeks - Public
OilRig Perfects Evasion Techniques with TwoFace Webshell
Unit 42 monitored OilRig's testing of the TwoFace webshell, specifically its TwoFace++ variant, to evade detection by security tools. Analysis revealed that OilRig's developers systematically modified the webshell's loader script to reduce detection rates, ultimately achieving zero detection by altering code related to the embedded payload's update functionality. The testing involved decoding and encrypting webshell data and frequent code alterations to pinpoint and circumvent security measures. Additionally, another webshell, named DarkSeaGreenShell, was discovered during these tests.
read more about OilRig Perfects Evasion Techniques with TwoFace Webshell - Public
APT34's Utilization of Microsoft Office Vulnerabilities to Compromise Middle Eastern Organizations
The Iranian cyber espionage group APT34 exploited two vulnerabilities (CVE-2017-0199 and CVE-2017-11882) in Microsoft Office to deliver malicious payloads against Middle Eastern governmental organizations. The group utilized spear-phishing emails with malicious .rtf files attached, which upon opening, exploited the vulnerabilities and executed malicious scripts. The scripts, POWRUNER and BONDUPDATER, performed actions such as persistence and command-and-control (C2) communication, including use of a domain generation algorithm (DGA) to evade detection.
read more about APT34's Utilization of Microsoft Office Vulnerabilities to Compromise Middle Eastern Organizations - Public
Flying Kitten to Rocket Kitten: Persistent Phishing Threats from Iran
The Iranian cyber groups Flying Kitten and Rocket Kitten exhibited overlapping tactics in credential theft and spearphishing, targeting entities in sectors like media, education, and technology across the UK, US, and Iran. Utilizing domains that mimicked legitimate services, such as Google and Microsoft, they orchestrated phishing campaigns to harvest user credentials. Their operations involved shared phishing toolkits and malware, including a keylogger, with connections back to Iranian infrastructure. Despite cessation of Flying Kitten activities post-2014, their tools and tactics were resurrected by Rocket Kitten, highlighting the persistent threat posed by these actors.
read more about Flying Kitten to Rocket Kitten: Persistent Phishing Threats from Iran - Public
MuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis
ReaQta's November 2017 report documents MuddyWater, an Iranian-linked APT group active throughout 2017 targeting government, telecom, and oil sector organizations in the Middle East — primarily Iraq, Saudi Arabia, and UAE. The group's primary backdoor, POWERSTATS, is a PowerShell-based in-memory implant that exemplifies "living off the land" tradecraft: it leaves no binary on disk, uses legitimate system tools for execution, and leverages compromised third-party websites as proxy C2 relays to conceal the real C2 server. ReaQta first identified MuddyWater in September 2017 when it discovered an active campaign using GitHub for payload hosting, then observed the group rapidly pivot to Pastebin after GitHub blocked their account, and subsequently embed the payload directly in the macro document. The group shifted C2 servers four times between September and November 2017 in response to public disclosures. Following Saudi Arabia's National Cybersecurity Center advisory in November 2017, MuddyWater added Koadic (a JScript RAT) and Meterpreter as secondary payloads. Key findings include: 10% of endpoints at a major Iraqi telecom provider were infected; 85% of victims ran Windows workstations with the remaining 15% being servers; operators showed high activity on Iraqi, Saudi, and UAE victims while largely ignoring Pakistani infections despite Pakistan having the most raw infections; attack hours were consistent with an Iranian work schedule. IOCs include 7 C2 IPs, 54 domains (compromised proxy sites), 74 C2 URLs, and 17 file hashes.
read more about MuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis - Public
MuddyWater Targets Middle East Using POWERSTATS Backdoor
The research team at Palo Alto Networks has discovered a group of targeted cyber-attacks against the Middle East region that occurred between February and October 2017, carried out by "MuddyWater". These attacks are espionage-related. The group used a PowerShell-based first-stage backdoor called "POWERSTATS", which evolved slowly over time, and targeted countries including the USA and India, as well as those within the Middle East like Saudi Arabia, Iraq, Israel, and the United Arab Emirates. The group also used GitHub to host its backdoor.
read more about MuddyWater Targets Middle East Using POWERSTATS Backdoor - Public
Continuing MuddyWater Phishing Campaign Targets Middle East and Pakistan
MuddyWater group continues its cyber-espionage operations, leveraging obfuscated PowerShell scripts within Word documents to infiltrate systems. These documents masquerade as legitimate entities, such as the Federal Investigation Agency of Pakistan. The tactics include sophisticated obfuscation techniques and a careful reconnaissance strategy, primarily focusing on the Middle East and Pakistan. The campaign deploys a variety of tools, including C&C servers and proxies, with a detailed focus on avoiding detection by analysis tools.
read more about Continuing MuddyWater Phishing Campaign Targets Middle East and Pakistan - Public
OilRig Threat Group Introduces ALMA Communicator in Spear-Phishing Attacks
The OilRig threat group has been utilizing a refined version of the Clayslide delivery document for spear-phishing attacks since May 2016. Recently, they have developed a new custom Trojan named "ALMA Communicator", and incorporated the use of Mimikatz for credential harvesting in the delivery phase of the attack. The targets included an individual at a public utilities company in the Middle East. ALMA Communicator uses DNS tunneling for C2 communication and has some data transfer limitations, which may have prompted the early deployment of Mimikatz.
read more about OilRig Threat Group Introduces ALMA Communicator in Spear-Phishing Attacks - Public
Potential Cyber Targets Revealed in Greenbug's Domain Registrations: Israeli and Saudi Firms in Focus
The Iranian threat agent Greenbug registered domains similar to Israeli high-tech and cybersecurity companies, as well as a Saudi Arabian electrical equipment firm. A sample of the ISMdoor malware was submitted from Iraq on October 15, 2017, indicating the threat actor's activities. Despite these registrations, no evidence of direct targeting or impact on these companies is present. High-tech, cybersecurity, online advertising, airport security systems, web development, behavioral biometrics, artificial intelligence, data security, and autonomous driving are sectors potentially of interest to the actor.
read more about Potential Cyber Targets Revealed in Greenbug's Domain Registrations: Israeli and Saudi Firms in Focus - Public
Inside OilRig's Attack on UAE Government: ISMInjector and CVE-2017-0199 Exploit in Play
The OilRig group launched a spear-phishing attack on an organization within the United Arab Emirates government on August 23, 2017. The phishing email contained two malicious attachments, and also used an image hosted on an adversary-owned server to potentially track email opens. OilRig likely gained access to a user's Outlook Web Access (OWA) account within the targeted organization to send phishing emails internally. The attachments included a document with a malicious macro and a file that attempted to exploit the CVE-2017-0199 vulnerability. The ultimate payloads were the new ISMInjector tool and the ISMAgent Trojan, with infrastructure linked to previous OilRig campaigns.
read more about Inside OilRig's Attack on UAE Government: ISMInjector and CVE-2017-0199 Exploit in Play - Public
Unveiling MuddyWater Phishing Campaign: Middle Eastern Governments in the Crosshairs
Entities in the Middle East, including Saudi Arabia and Iraq, were targeted by an early MuddyWater phishing campaign predominantly aimed at the government sector. Spear-phishing emails carrying malicious attachments were a key tactic, with PowerShell scripts being sourced from Pastebin and Filebin. To avoid detection, the attackers concealed their scripts. Upon examining the macro code and command and control scripts, parallels were found with a campaign previously discussed by Morphisec.
read more about Unveiling MuddyWater Phishing Campaign: Middle Eastern Governments in the Crosshairs - Public
Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs
Palo Alto Networks Unit 42's September 2017 report documents OilRig's adversary infrastructure by tracing activity from a previously discovered TwoFace web shell. Researchers identified a network of 14 C2 IP addresses and 7 credential-harvesting domains — all designed to spoof the webmail portals of specific Israeli targets, including Tel Aviv University, Hebrew University of Jerusalem, Bezeq International, Macro Advisory Partners, Tidhar Group, and the Institute for National Security Studies. The harvesters were exact replicas of the legitimate login pages, indicating a targeted credential theft mission against Israel-connected organizations. Analysis of tools uploaded to compromised web servers revealed OilRig's post-exploitation toolkit: Mimikatz (credential dumping), PsExec (remote execution), PuTTY Link/Plink (SSH tunneling for lateral movement), and RGDoor (a custom IIS backdoor for persistent fallback access). Two additional web shells — RunningBee (password-protected) and LittleFace (command execution via HTTP POST) — were also identified. A shared Mimikatz sample linked TwoFace and OilRig infrastructure, establishing tactical overlap between the two campaigns. Targeted sectors included think tanks, universities, strategic consulting firms, real estate companies, and telecommunications providers across the Middle East, with a heavy focus on Israeli interests.
read more about Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs - Public
Saudi Arabian Government Hit by Stealthy Macro Malware
A Saudi Arabian Government entity has been targeted by an innovative attack that relies on macros within malicious Word documents and leverages various scripts rather than a binary payload. The attack uses a VBScript to lower security settings within Microsoft Word and Excel and fetches data from Pastebin. A PowerShell script then communicates with the C2 server and exfiltrates data, persistently remaining undetected and continuing to collect information from the targeted system. The primary targeted sector is the Government.
read more about Saudi Arabian Government Hit by Stealthy Macro Malware - Public
Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea
Mandiant's September 2017 report provides the foundational profile of APT33, an Iranian state-sponsored espionage group active since at least 2013. The group targeted organizations in the United States, Saudi Arabia, and South Korea, with a strong focus on the aerospace and energy sectors — particularly companies with military aviation ties and petrochemical production. Between mid-2016 and early 2017, APT33 compromised a U.S. aerospace organization and targeted Saudi and South Korean conglomerates with aviation and oil refining operations. Intrusions began with spearphishing emails carrying malicious HTML Application (.hta) files disguised as aviation job postings, sent via the publicly available ALFA TEaM Shell. APT33 registered lookalike domains impersonating Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia to lend credibility to phishing lures. The group's primary backdoor, TURNEDUP, was deployed via the DROPSHOT dropper; commodity RATs including NANOCORE and NETWIRE were also used. Mandiant also identified links between DROPSHOT and the SHAPESHIFT disk-wiping malware, raising concerns about APT33's potential for destructive operations. Attacker activity aligned with Iranian working hours (UTC+4:30) and the Iranian Saturday-to-Wednesday workweek, supporting attribution to Iran.
read more about Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea - Public
The Base64 Disguise: How GreenBug's Trojan ISMAgent Evades Detection
ClearSky Research Team documents new ISMAgent samples and infrastructure used by the Iranian threat group Greenbug in August 2017. The delivery chain begins with a malicious Word template file named "change managment.dot" that exploits CVE-2017-0199, a remote code execution vulnerability in Microsoft Office. Exploiting this vulnerability causes the document to reach out to msoffice-cdn[.]com and retrieve a remote template (template.rtf), which in turn executes a hidden PowerShell command. The PowerShell command downloads a file called ntluca.txt from a.pomf[.]cat — a file that appears to be a base64-encoded digital certificate but is actually an ISMAgent payload. The file is decoded on disk using the legitimate Windows utility certutil.exe, producing the ISMAgent executable (srvConhost.exe) which is then run silently. ClearSky provides a Maltego-based infrastructure graph mapping the relationships between the IOCs, including C2 IPs (74.91.19[.]122, 82.102.14[.]246, 185.162.235[.]121), domains (cdnmsnupdate[.]com, msoffice-cdn[.]com), and WHOIS registrant data (neslihan.ovcivit@mail.ru). Several of these IOCs overlap with OilRig infrastructure documented in a concurrent Palo Alto Networks report, suggesting shared or coordinated infrastructure between the two Iranian-linked groups. Source URL is no longer directly accessible; this analysis is based on the archived PDF attachment.
read more about The Base64 Disguise: How GreenBug's Trojan ISMAgent Evades Detection - Public
Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities
In February 2017, an evolution of the "Infy" malware, named "Foudre" ("lightning" in French), was observed, demonstrating advanced anti-takeover techniques. Foudre, mostly written in Delphi, includes keylogging, clipboard content capture, and system information collation, aiming to evade previous countermeasures like C2 domain sinkholing. It checks internet connectivity, updates itself, and uses a Domain Generation Algorithm (DGA) for C2 domain validation. Infected via spear-phishing emails with self-executable attachments, Foudre establishes persistence by modifying the registry and using a DLL loader mechanism. It exfiltrates data via HTTP POST and employs new C2 defense mechanisms, including RSA signature verification. The report, however, does not specify targeted countries or sectors.
read more about Foudre: The Advanced Evolution of Infy Malware with Enhanced Anti-Takedown Capabilities - Public
TwoFace Webshell: Persistent Threat in Middle Eastern Networks
Unit 42 uncovered the TwoFace webshell, a sophisticated dual-component tool used by attackers for prolonged unauthorized access within a Middle Eastern organization's network. The TwoFace webshell enabled execution of various commands and facilitated lateral movement by copying itself across servers. The intruders utilized Mimikatz to harvest credentials and orchestrated their attacks from multiple international IP addresses, suggesting a broad geographic operational footprint. Analysis revealed that the attackers maintained access since at least June 2016, using obfuscated C# code on ASP.NET servers to remain undetected and manage the webshell payload.
read more about TwoFace Webshell: Persistent Threat in Middle Eastern Networks - Public
Mia Ash: Anatomy of a cyber espionage persona, COBALT GYPSY lures middle eastern targets
The article "The Curious Case of Mia Ash" by SecureWorks details a sophisticated cyber espionage campaign. This campaign involved a fake online persona named Mia Ash, created by the threat group COBALT GYPSY, which is associated with Iranian cyber operations. Mia Ash was used to establish relationships with employees in targeted organizations, primarily in the Middle East and North Africa. The persona, active across various social media platforms, was instrumental in delivering malware through seemingly innocent interactions. The case underlines the increasing complexity of cyber threats where social engineering and fake identities are employed to breach security systems.
read more about Mia Ash: Anatomy of a cyber espionage persona, COBALT GYPSY lures middle eastern targets - Public
CopyKittens: Espionage Campaign Targeting Strategic Sectors Across the Globe
Operation Wilted Tulip, jointly published by ClearSky and Trend Micro in July 2017, exposes CopyKittens' full espionage apparatus active since 2013. The group targeted government institutions (including Ministries of Foreign Affairs), academic institutions, defense companies, IT companies, and media outlets across Israel, Saudi Arabia, Turkey, the US, Jordan, and Germany — with UN employees also targeted. Five delivery methods were documented: watering hole attacks inserting BeEF (Browser Exploitation Framework) JavaScript into breached news websites (Jerusalem Post, Maariv, IDF Disabled Veterans Organization); web-based exploitation using browser fingerprinting code served from attacker-built sites after compromising email accounts at target organizations; malicious documents exploiting CVE-2017-0199 (Word/HTA RCE), embedding OLE objects with RTLO (right-to-left override) extension spoofing, and macro-based execution; fake Facebook profiles and a fake Israeli news aggregator ("Emet press," built on NovinWebGostar — an Iranian web development platform) to build target trust; and SQL injection via Havij, sqlmap, and Acunetix against internet-facing web servers. Custom malware included TDTESS backdoor, Matryoshka v1/v2 RAT, Vminst (lateral movement tool injecting Cobalt Strike via stolen credentials), NetSrv (Cobalt Strike loader), and ZPP (file compressor for exfiltration). Public tools used include Cobalt Strike (trial version), Metasploit, Mimikatz, and Empire. DNS tunneling was the primary C2 channel in both Cobalt Strike and Matryoshka. A shared AI Squared digital certificate found in CopyKittens samples had also been used by OilRig, suggesting possible resource sharing or collaboration between the two groups. A developer username "shiranz" appeared in metadata of multiple samples, providing a consistent attribution artifact.
read more about CopyKittens: Espionage Campaign Targeting Strategic Sectors Across the Globe - Public
Greenbug Group's Escalated Threat: Ismdoor RAT's Role in the Shamoon Attacks
NETSCOUT's ASERT team documents a significant evolution in Ismdoor, the custom remote access trojan used by the Iranian-linked Greenbug cyberespionage group. Where earlier versions used HTTP for command and control, the versions analyzed here replaced that entirely with a covert DNS-based C2 channel — communicating exclusively through AAAA DNS queries, encoding data as IPv6 addresses. The protocol is multi-layered: sessions are established via specially formatted query names containing a 32-character hex session ID, messages are base64-encoded and embedded in query subdomains, and responses are returned as static or data-carrying IPv6 addresses. File transfers use a separate session type with retransmission logic for missed packets. The malware supports over 20 C2 commands, including system information collection, self-update, credential dumping via Mimikatz (CreateMimi1Bat command invoking ccd61.ps1), keylogging (ExecuteKL), Powercat execution for network tunneling (ExecutePC), UAC bypass via RAAD, screenshot capture (PWS), and arbitrary command shell execution. Configuration is encrypted with a consistent substitution cipher and contains primary and secondary C2 domains, timeout values, and a unique bot identifier. NETSCOUT presents four indicators linking Ismdoor to the Shamoon/Disttrack campaigns against Saudi Arabia: Symantec observed an earlier Ismdoor variant on a Shamoon-targeted host shortly before Disttrack was deployed; all known DNS-variant samples were submitted to VirusTotal from Saudi Arabia; the CreateMimi1Bat command provides explicit credential-theft capability; and a McAfee blog on Shamoon traces a spearphishing email to the download and execution of an earlier Ismdoor variant. The link remains assessed as probable but unconfirmed at time of publication.
read more about Greenbug Group's Escalated Threat: Ismdoor RAT's Role in the Shamoon Attacks - Public
OilRig's Developmental Tactics: Evading Antivirus Through Rigorous Testing
Palo Alto Unit42 documents the earliest known example of OilRig's systematic AV evasion testing process, conducted in June and November 2016 against their ClaySlide delivery documents — the same organized methodology Unit42 would later observe again in the 2018 BONDUPDATER campaign. In June 2016, OilRig created a base test file on June 13 and then ran 17 iterative modifications over a 2-hour window on June 15, starting at 4 AV detections and ending at 0. In November 2016, a second testing session generated 7 iterations in approximately 30 minutes on November 15 (following a base file on November 14), reducing detections from 5 to 2. Both sessions used the same pattern: upload to a public AV scanning service, measure the detection count, make one targeted change, re-upload, repeat. The June testing covered: payload removal (to isolate macro detection), removal and re-addition of the scheduled task creation block, command encoding experiments (base64, hexadecimal), intentional misspellings of key strings ("poawearshell", "scshtassks"), use of a FireEye blog URL as a base64 filler to test string-based detection, keyboard mashing, variable/function renaming, folder path changes, and reverting to the base document to restart the process. The November testing focused on decoy worksheet modifications (changing worksheet name, content, and sheet hash), function name obfuscation (Doom_Init → Doon_Init → Ini), variable name changes (BackupVbs → Backup_Vbs), string concatenation of the scheduled task creation command, and moving payload storage locations within the spreadsheet cells. The June campaign used C2 domain update-kernal[.]net; the November campaign used updateorg[.]com with the same Helminth payload. Unit42 assesses this testing behavior reflects a professionally organized operations model in which delivery documents are extended for as long as possible through iterative evasion refinement.
read more about OilRig's Developmental Tactics: Evading Antivirus Through Rigorous Testing