Threats Feed
- Public
OilRig Campaign Resurfaces: Iranian Hackers Target Israel with Helminth Trojan
Between April 19-24, 2017, several Israeli organizations, including high-tech development companies, medical entities, and educational institutions were targeted by a politically motivated campaign attributed to the Iranian hacker group responsible for the OilRig malware campaigns. The fileless attack was delivered through compromised email accounts at Ben-Gurion University using Microsoft Word documents exploiting the CVE-2017-0199 vulnerability. The Helminth Trojan was installed as a result, bearing a striking similarity to the OilRig campaign conducted against Middle Eastern financial institutions the previous year. The threat actors exploited the gap between patch release and rollout, with active C&C servers still operational at the time of report publication.
read more about OilRig Campaign Resurfaces: Iranian Hackers Target Israel with Helminth Trojan - Public
CopyKittens Targets Israeli Media and Palestinian Healthcare in Watering Hole Attacks
The Iranian threat agent CopyKittens compromised multiple Israeli websites, including the Jerusalem Post, and one Palestinian Authority website between October 2016 and January 2017. The attackers bought access to the server to gain the access, inserting a single line of Javascript into existing libraries. This enabled them to load further malicious Javascript from a domain they controlled, selectively targeting users based on their IP addresses. The malicious payload used was the BeEF Browser Exploitation Framework.
read more about CopyKittens Targets Israeli Media and Palestinian Healthcare in Watering Hole Attacks - Public
CopyKitten’s Spearphishing Attack on Israeli Ministry of Communications
CopyKitten, a known cyber-attack group, has launched a spearphishing campaign targeting the Israeli government’s Ministry of Communications. The investigation commenced with the identification of a suspicious domain that led to multiple related domains. One such domain closely mimicked the Israeli Prime Minister's SSL VPN login page and was used to drop a malicious Word document titled "Annual Survey.docx." This document had an embedded OLE object that communicated with a C2 server, signifying a well-planned attack. The campaign appears to be part of CopyKitten's ongoing activities against Israeli interests.
read more about CopyKitten’s Spearphishing Attack on Israeli Ministry of Communications - Public
Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets
Beginning in late 2016, Shamoon 2.0 and the newly discovered StoneDrill malware launched destructive wiper attacks against critical and economic sectors in Saudi Arabia, with evidence of StoneDrill reaching European targets. Shamoon 2.0, a successor to the 2012 Saudi Aramco attack tool, incorporated stolen administrator credentials, automated worm-like spreading, disk wiping, and even inactive ransomware capabilities. StoneDrill introduced advanced sandbox evasion, injected its payload into browsers, and targeted accessible files or full disks. Both malware families used obfuscation, anti-analysis tricks, and in Shamoon’s case, signed drivers for low-level destruction. StoneDrill shared code similarities with the NewsBeef (aka Charming Kitten) APT, suggesting broader regional targeting and actor overlap.
read more about Shamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets - Public
Disttrack Malware Decimates Saudi Critical Infrastructure
The BlackBerry Cylance threat research team's report offers a comprehensive analysis of the Disttrack malware, also known as Shamoon, renowned for its devastating attacks on system master boot records. The report traces the malware's history, its resurgence, and explores its technical operations, including network management capabilities and modular architecture. It particularly highlights Disttrack's impact on Saudi Arabia's critical infrastructure, demonstrating its potential for significant damage. This abstract succinctly captures the essence of the malware's threat and operational dynamics for a general audience.
read more about Disttrack Malware Decimates Saudi Critical Infrastructure - Public
Unraveling Greenbug Group's RAT: Keylogging, Powercat, and Beyond
NCC Group's Ahmed Zaki provides the first detailed technical analysis of ISM RAT (Ismdoor) version 5.0.0, the HTTP-based variant used by the Greenbug group before the group later switched to DNS tunneling. NCC identifies three versions of the RAT in the wild; v5.0.0 is the most capable, adding keylogging (WinIt.exe), Powercat-based shell access on port 4444, Mimikatz credential dumping, and UAC bypass via Invoke-BypassUAC and Invoke-PsUACme — the latter suspected to be from the Nishang PowerShell framework. All C2 communication uses HTTP POST requests to update.winappupdater[.]com with a WinHTTPClient user agent; key endpoints include /Home/CC (connection check), /Home/CR (command receive), /Home/AV (alive), and /Home/SCV (command result reporting). The SI command collects extensive system reconnaissance: username, IP configuration, network connections, running tasks, services, and installed AV/firewall products via WMIC — all written to a temporary .txt file and exfiltrated. NCC notes that the RAT's authors copy-pasted WinHTTP code directly from MSDN examples, left debugging messages in release builds, and used an unusual method to retrieve %TEMP% via a command prompt rather than the standard Windows API — leading the analysts to conclude the group is not technically sophisticated despite the breadth of their tooling. The RAT uses timer-queue callbacks for thread management and is assessed to be under active development given ongoing code refactoring and the introduction of versioning. Source URL is no longer accessible; this analysis is based on the archived PDF attachment.
read more about Unraveling Greenbug Group's RAT: Keylogging, Powercat, and Beyond - Public
Magic Hound Strikes Saudi Arabia with Spearphishing and PowerShell Attacks
The report details the Magic Hound cyber campaign targeting primarily Saudi Arabia. The campaign leveraged spearphishing emails with malicious attachments and links, PowerShell scripts, Windows Command Shell, and obfuscation techniques like XOR and Base64 encoding. Additionally, the attackers utilized HTTP and HTTPS protocols for command and control communication.
read more about Magic Hound Strikes Saudi Arabia with Spearphishing and PowerShell Attacks - Public
COBALT GYPSY's Yet Another PupyRAT-driven Phishing Campaign
SecureWorks researchers identified a phishing campaign targeting a Middle Eastern organization in January 2017, linked to COBALT GYPSY (Aka OilRig). The attackers employed spear-phishing emails containing shortened URLs redirecting to spoofed domains. Victims were presented with a malicious Microsoft Office document, which executed PowerShell commands when opened, installing PupyRAT, a multi-platform remote access trojan (RAT).
read more about COBALT GYPSY's Yet Another PupyRAT-driven Phishing Campaign - Public
MacDownloader: Early Iranian Malware Efforts Target Defense and Human Rights Sectors
The MacDownloader malware, initially observed targeting the defense industrial base and a human rights advocate, impersonates legitimate software like Adobe Flash Player and Bitdefender Adware Removal Tool to steal system information and macOS Keychain data. It reflects initial development efforts by possibly amateur Iranian-affiliated actors and is linked to previously documented Iranian operations targeting aerospace and defense employees. The malware, which also gathers user credentials, lacks effective persistence features and uses similar infrastructure as previous campaigns attributed to the Iranian group Charming Kitten.
read more about MacDownloader: Early Iranian Malware Efforts Target Defense and Human Rights Sectors - Public
The Possible Connection Between Greenbug and Shamoon Revealed
The Greenbug cyberespionage group, active since June 2016, has been using Trojan.Ismdoor, a custom information-stealing remote access Trojan (RAT), and additional hacking tools to compromise organizations in the Middle East and a Saudi organization in Australia. The group targets sectors including aviation, energy, government, investment, and education, using spearphishing emails to deliver malicious payloads hidden in RAR archives. Once opened, the Trojan opens a backdoor and collects sensitive data, potentially facilitating further attacks. Notably, the group’s activity ceased a day before the destructive W32.Disttrack.B (Shamoon) attack in November 2016, suggesting a possible connection.
read more about The Possible Connection Between Greenbug and Shamoon Revealed - Public
Stolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks
The Iranian threat agent OilRig, active since the end of 2015, has been implicated in a wave of cyber attacks targeting several countries, namely Israel, Turkey, Qatar, Kuwait, UAE, Saudi Arabia, and Lebanon. In their most recent campaigns, they have leveraged advanced strategies, setting up fake VPN portals, counterfeit websites, and using stolen code signing certificates to give their malware an appearance of authenticity. This not only illustrates their high technical capability, but also underscores the complexity and effectiveness of their operations. These attacks have largely targeted IT and financial institutions, causing significant concerns in these sectors.
read more about Stolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks - Public
Shamoon 2.0 Resurfaces in the Gulf States with Enhanced Cyberattack Tactics
In mid-November 2016, Mandiant responded to the Shamoon 2.0 malware attack targeting organizations in the Gulf states, marking the return of the suspected Iranian hacker group "Cutting Sword of Justice." This updated version of the 2012 Shamoon malware features embedded credentials, suggesting previous targeted intrusions for credential harvesting. Shamoon 2.0 performs subnet scanning, uses domain-specific credentials for unauthorized access, modifies system registries, and schedules tasks for execution. Its payload involves overwriting system files and wiping boot records, notably shifting imagery from a burning U.S. flag to a photograph of Alan Kurdi, symbolizing a devastating critique through cyber vandalism.
read more about Shamoon 2.0 Resurfaces in the Gulf States with Enhanced Cyberattack Tactics - Public
The Resurgence of Shamoon: How Stolen Credentials Enable Destructive Cyberattacks
Shamoon, the destructive disk-wiping malware that crippled tens of thousands of Saudi Aramco workstations in 2012, resurfaced in November 2016 in a new wave of attacks against Saudi Arabian organizations. The updated variant, W32.Disttrack.B, closely mirrors its predecessor: it overwrites master boot records with a politically themed image and renders infected systems unbootable. Critically, the attackers did not exploit software vulnerabilities — they used legitimate, pre-stolen credentials to authenticate across the network and deploy the malware at scale. The malware itself consists of three components: a dropper that installs the package, a wiper that destroys data and overwrites the MBR, and a reporter module that communicates results back to a command-and-control server. Symantec's analysis identified a direct link to the Greenbug espionage group, whose activity on at least one targeted network ceased the day before Shamoon detonated — strongly suggesting Greenbug served as the initial access broker that collected the credentials enabling the attack.
read more about The Resurgence of Shamoon: How Stolen Credentials Enable Destructive Cyberattacks - Public
Shamoon 2: The Return of Disttrack's Destructive Force in Saudi Arabia
The Shamoon 2 campaign, a resurgence of the 2012 Shamoon attacks, targeted a Saudi Arabian organization to deliver the Disttrack malware, focusing on data destruction. Disttrack, comprised of dropper, communication, and wiper components, utilized stolen administrator credentials for network propagation and was designed to render infected systems unusable by overwriting data with politically motivated images. This attack notably aimed for maximum impact by initiating the wipe at the end of the Saudi workweek, exploiting periods when recovery efforts would be delayed. The lack of a functioning C2 server indicated a sole focus on destruction rather than espionage or data exfiltration.
read more about Shamoon 2: The Return of Disttrack's Destructive Force in Saudi Arabia - Public
OilRig Campaign: Malware Updates and Expanded Global Targets
The OilRig cyberattack campaign, first analyzed in May 2016, continues to evolve, targeting government organizations and companies in Saudi Arabia, Qatar, Turkey, Israel, and the United States. Using spear-phishing emails with malicious Microsoft Excel documents, the attackers have updated their toolset, including Clayslide delivery documents and the Helminth backdoor. The malware communicates with remote servers via HTTP and DNS for command and control. Despite its lack of sophistication, the malware successfully operates under the radar in many establishments due to techniques like DNS command and control.
read more about OilRig Campaign: Malware Updates and Expanded Global Targets - Public
Iranian-Linked Group5 Targets Syrian Opposition with Multi-Platform Malware
Citizen Lab researchers identified Group5, a threat actor with probable Iranian ties, conducting a multi-platform surveillance campaign against members of the Syrian political opposition. The operation began in October 2015 when Noura Al-Ameer, a senior Syrian National Council official, received a spearphishing email carrying a malicious PowerPoint slideshow (PPSX) designed to look like Iranian human-rights documentation. The attackers also set up a watering hole site — assadcrimes[.]info — that distributed both Windows and Android malware. On the Windows side, Group5 deployed njRAT and NanoCore RAT, both obfuscated with a Persian-language crypter called PAC Crypt. One of the PowerPoint files exploited CVE-2014-4114 to silently install the RAT. On Android, a fake Adobe Flash Player update delivered DroidJack, granting the operator remote access to calls, messages, contacts, camera, and microphone. Website logs left publicly accessible revealed the operators accessing the site from Iranian IP space, including addresses belonging to Rightel, an Iranian mobile carrier, pointing to an Iranian operational nexus.
read more about Iranian-Linked Group5 Targets Syrian Opposition with Multi-Platform Malware - Public
Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims
The report details a decade-long cyber campaign by unidentified attackers, primarily targeting Iranian citizens among others in 35 countries. Despite the publication of an initial report, the attackers continued using the same encoding key for their operations. The defenders successfully sinkholed most of the campaign's command and control (C2) domains, limiting the attackers' communications with the majority of the victims. Analysis revealed the use of two malware variants, Infy and the more sophisticated Infy "M", with the latter being updated more regularly and targeting higher-value individuals. The attackers also attempted to evade detection by modifying their malware and adding new C2 infrastructure, including domain names and IP addresses.
read more about Decade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims - Public
OilRig Group Unleashes Coordinated Cyber Campaigns on Saudi Arabian Industries
Palo Alto Unit42 introduces the OilRig campaign — naming both the threat group and the Helminth backdoor based on the Persian word "Nafti" (نفتی, meaning "oily") found hardcoded alongside philosopher names (Plato, Arasto, ALAfghani) in malware samples. The report documents two waves of targeted attacks on Saudi Arabian organizations across the financial, technology, defense, and telecommunications sectors: an August 2015 wave using fake job offers to deliver the Helminth executable variant, and a May 2016 wave using a service-provider social engineering theme to deliver the Helminth script variant via Clayslide Excel macro documents. The Clayslide delivery documents display a fake "Incompatible" worksheet instructing the user to enable macros, after which they show legitimate-looking decoy content (internal IP status tables) while installing Helminth's two-component script variant: update.vbs (HTTP C2 for batch script download and output upload) and dns.ps1 (DNS-based C2 using IP address octets as data transport, with 33.33.x.x as a start marker and 35.35.x.x as a stop marker). Both scripts create a fully functional remote shell. The executable variant, delivered via the HerHer dropper Trojan, adds a keylogger module (wintrust.hlm DLL) that monitors keystrokes and clipboard contents. Both variants beacon hardcoded per-sample "Group" (targeted organization name) and "Name" (philosopher/Persian word) values in C2 traffic, confirming deliberate pre-operational targeting. WHOIS registrant data for C2 domains included Iranian email addresses (chmail.ir provider, Tehran geolocation), consistent with Iranian-based operators. The scheduled task "GoogleUpdateTaskMachineUI" ran update.vbs every three minutes.
read more about OilRig Group Unleashes Coordinated Cyber Campaigns on Saudi Arabian Industries - Public
APT34 Targets Middle Eastern Banks with Macro Malware
APT34 launched targeted attacks against banks in the Middle East in May 2016. The threat actors sent malicious macro-enabled XLS files in emails to banking sector employees, which then created multiple directories and dropped PowerShell scripts to perform various malicious activities. The macros also unhidden content post-execution, creating a false sense of legitimacy. These files executed various scripts to download additional payloads, gather information, and exfiltrate data over DNS queries, demonstrating the continued effectiveness of macro malware.
read more about APT34 Targets Middle Eastern Banks with Macro Malware - Public
Decade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government
The Infy malware, active since 2007 and still operational as of April 2016, was identified by Palo Alto Networks WildFire. Spear-phishing emails with malicious Word or PowerPoint attachments were sent from compromised accounts, targeting Israeli industrial organizations and a U.S. Government entity. These emails contained a multi-layer Self-Extracting Executable Archive, designed to deceive recipients into executing it. The malware, capable of evading antivirus detection, collected keylogs, browser passwords, and other sensitive data, which was then exfiltrated to C2 servers. These servers utilized a mix of Dynamic DNS providers, third-party site hosting, and first-party-registered domains. The malware's focus on specific geographic areas and sectors suggests a well-planned and targeted cyber espionage campaign against government and industrial entities in Israel, Denmark and the United States.
read more about Decade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government - Public
NewsBeef APT Revives BeEF for Global Watering Hole Campaigns
In early 2016, the NewsBeef APT (aka Charming Kitten/Newscaster) repurposed the open-source BeEF and Metasploit frameworks in widespread watering hole attacks. These operations targeted visitors to strategically compromised websites, including institutions in Iran, Russia, India, Ukraine, the EU, Turkey, Germany, Japan, China, Brazil, and more. Sectors impacted included education, military, diplomacy, manufacturing, and media. The attackers injected malicious JavaScript to hook browsers, track visitor behavior, and fingerprint systems using evercookies and browser enumeration. While full exploitation wasn’t always observed, selective delivery of backdoors or spoofed login prompts was reported. The group’s campaign reflects an evolution from low-tech social engineering to more technically advanced infrastructure attacks using open-source tools.
read more about NewsBeef APT Revives BeEF for Global Watering Hole Campaigns - Public
SamSam Ransomware Exploits JBoss Servers, Targets Healthcare Sector
The SamSam ransomware campaign exploited vulnerabilities in public-facing JBoss application servers, leveraging JexBoss for initial access. The attackers gained a foothold, moved laterally across networks, and deployed SamSam ransomware to encrypt Windows systems. The healthcare sector was a primary target, with ransom demands increasing over time—from 1 BTC per system to 1.7 BTC. Attackers also introduced a bulk decryption option for 22 BTC. REGeorg's tunnel.jsp was used to maintain access. The malware employed Rijndael encryption with RSA-2048 key wrapping, rendering files unrecoverable without payment. The campaign demonstrated a shift from phishing to direct server exploitation, highlighting the evolving nature of ransomware attacks.
read more about SamSam Ransomware Exploits JBoss Servers, Targets Healthcare Sector - Public
Chafer and Cadelle: Unveiling Iran's Persistent Cyber Surveillance on Middle Eastern Targets
Symantec researchers identified two Iran-based threat groups, Cadelle and Chafer, conducting targeted surveillance operations against individuals and organizations in Iran and across the Middle East. Active since at least July 2014, the groups deployed custom-built backdoor malware — Backdoor.Cadelspy and Backdoor.Remexi — capable of keystroke logging, audio recording, screen capture, and remote command execution. Their primary targets included telecommunications providers and airlines in the Middle East, likely to monitor the movements and communications of persons of interest. Symantec assessed that the attackers operated during Iranian business hours, and that their victim profile aligns with the intelligence interests of an Iranian state entity. Both groups were confirmed to still be active at the time of publication.
read more about Chafer and Cadelle: Unveiling Iran's Persistent Cyber Surveillance on Middle Eastern Targets - Public
CopyKittens Cyber Espionage Targets Israeli Diplomats and Researchers
ClearSky and Minerva Labs' November 2015 report exposed CopyKittens, characterizing them as a "mid-level" group that assembled their attack platform largely from public code repositories — hence the name. The campaign targeted high-ranking Israeli diplomats at the Ministry of Foreign Affairs (including an Israeli ambassador in a large eastern European country) and Israeli academic researchers specializing in Middle East Studies. Three spearphishing waves were observed in 2015, using carefully tailored email subjects such as "Registration form to the United Nations CTITF," "Israeli MFA questionnaire – URGENT," and "Israel Ministry of Foreign Affairs Diplomatic List." Attachments were Word documents containing OLE-embedded SCR executables whose filenames used the RTLO Unicode character (U+202E) to display as PDFs (e.g., Quest__fdp.scr displayed as Quest__rcs.pdf). The Matryoshka framework operated in four stages: (1) the SCR dropper unpacked the reflective loader, signaled the C2 by downloading a PNG image, and ran a modified Pafish sandbox check — returning numeric codes 1–27 for detected artifacts and reporting back before terminating if analysis was detected; (2) the reflective loader used Stephen Fewer's Reflective DLL Injection to inject the RAT library into a legitimate running process without writing it to disk; (3) the RAT component established persistence via a registry Run key ({0355F5D0-467C-30E9-894C-C2FAEF522A13} under CurrentVersion\Run pointing to kernel.dll via rundll32.exe) and a scheduled task named "Microsoft Boost Kernel Optimization" running every 20 minutes; (4) C2 communication occurred over DNS, with queries obfuscated using a substitution cipher and data encoded in subdomains — responses used IP addresses from Microsoft and McAfee address blocks to lower SOC suspicion. The RAT's capabilities included Outlook password theft (specific IP response 134.170.185.13 triggered this), screen capture, and keylogging — all assembled from public forum code. All three C2 IPs were hosted at XLHost.com.
read more about CopyKittens Cyber Espionage Targets Israeli Diplomats and Researchers