Threats Feed
- Public
Iran-Based TG-2889 Uses Fake LinkedIn Network to Target Middle East Telecom and Defense
In October 2015, Dell SecureWorks Counter Threat Unit (CTU) researchers uncovered a network of 25 fake LinkedIn profiles created by TG-2889, a suspected Iran-based threat group linked to Operation CLEAVER. The fake accounts were divided into two tiers: eight "Leader" personas with detailed professional histories, 500+ connections, and skills endorsements — purporting to work for companies including Teledyne Technologies, Northrop Grumman, Doosan, and Petrochemical Industries Co. — and 17 simpler "Supporter" personas designed solely to endorse the Leader accounts and artificially boost their credibility. Five Leader personas posed as recruitment consultants, providing a natural pretext to approach targets with job offers. CTU researchers identified 204 likely victims based on users who had endorsed the fake Leader profiles; a quarter worked in telecommunications (Middle Eastern and North African mobile operators featured heavily), with significant minorities in Middle Eastern governments and defense organizations. The threat actors also demonstrated a novel technique — replacing one persona's identity with another on the same LinkedIn account, inheriting the accumulated network and endorsements while refreshing the cover identity. Fake domains matching the impersonated companies (teledyne-jobs[.]com, doosan-job[.]com, northropgrumman[.]net) link TG-2889 to the Operation CLEAVER malware campaign documented by Cylance, which used fake job application portals to deliver malware. The group's geographic focus on Arab states in the MENA region is consistent with Iran-based threat actor targeting.
read more about Iran-Based TG-2889 Uses Fake LinkedIn Network to Target Middle East Telecom and Defense - Public
Thamar Reservoir: Iranian Cyber Campaign Targets Middle East Sectors
Clearsky's "Thamar Reservoir" report details a sustained Iranian cyber-attack campaign targeting over 550 individuals, primarily in the Middle East. The attacks, which began in 2014, used a variety of techniques, including spear-phishing emails with malware, phone calls, and compromised websites to create fake login pages. The attackers were persistent but lacked technical sophistication and made mistakes that aided the investigation. The report concludes that the campaign's targets and methods strongly suggest Iranian state sponsorship, and links it to other known Iranian cyber operations.
read more about Thamar Reservoir: Iranian Cyber Campaign Targets Middle East Sectors - Public
Rocket Kitten’s Operation Woolen-GoldFish Targets Israeli and European Organizations
This Trend Micro report details the activities of Rocket Kitten, a cyber threat group targeting Israeli and European organisations. The report focuses on two campaigns: a malware campaign using the GHOLE malware, possibly dating back to 2011, and a suspected state-sponsored operation, 'Operation Woolen-GoldFish', involving spear-phishing attacks. Analysis shows possible links to an individual using the alias "Wool3n.H4t", possibly Iranian, and highlights the group's increasing sophistication despite using relatively simple techniques such as macros. The overall aim is to inform readers of Rocket Kitten's methods and suspected politically motivated objectives, suggesting Iranian involvement.
read more about Rocket Kitten’s Operation Woolen-GoldFish Targets Israeli and European Organizations - Public
Gholee Malware Exploits Israel-Gaza Conflict Theme in Targeted Cyberattack
During the 2014 Israel-Gaza conflict, an operation themed "protective edge" spear phishing campaign emerged, targeting Israeli entities. The Gholee malware, delivered via a malicious Excel file named ‘Operation Protective Edge.xlsb’, utilized social engineering and VBA macro execution to compromise systems. The malware featured advanced obfuscation and evasion techniques, including ASCII character encoding and debugger detection, to avoid security measures. It communicated with a server in Kuwait, using an outdated SSL certificate, suggesting sophisticated threat actors possibly linked to state-sponsored activities.
read more about Gholee Malware Exploits Israel-Gaza Conflict Theme in Targeted Cyberattack - Public
Iranian Ajax Security Team Conducts Espionage on U.S. Defense Contractors
FireEye's May 2014 Operation Saffron Rose report documents the Ajax Security Team's transition from website defacements (active 2010–2013) to malware-based espionage. The group used three parallel attack vectors: spearphishing emails impersonating the IEEE Aerospace Conference (aeroconf2014[.]org, registered under keyvan.ajaxtm@gmail.com, linking directly to Ajax Security Team leader "HUrr!c4nE!"); credential-phishing pages mimicking Outlook Web Access and VPN login portals targeting US defense industrial base companies; and trojanized anti-censorship software (Psiphon, Ultrasurf, Gerdoovpn, Proxifier) distributed to Iranian users and dissidents. The custom Stealer malware — a .NET dropper deploying IntelRS.exe and AppTransferWiz.dll — collected system info, performed keylogging, took screenshots, harvested browser credentials (Chrome, Firefox, Opera, IE), extracted IM account data (GTalk, Pidgin, Yahoo, Skype), and RDP credentials. Stolen data was AES-256 encrypted locally using the Persian passphrase "HavijeBaba" (salt: "salam!*%#") before FTP exfiltration to actor-controlled C2 infrastructure. FireEye recovered data from 77 victims on one C2 server — 44 had timezone set to "Iran Standard Time" and 37 also had Persian language settings, confirming the anti-censorship campaign targeted Iranian users inside Iran. The campaign's infrastructure linked three clusters via shared IPs, with the registration trail tracing directly to "HUrr!c4nE!" (aka k3yv4n), founder of the Ajax Security Team. The Stealer Builder (compiled 2014-04-08) allowed operators to configure custom C2 credentials and bind the backdoor to legitimate applications.
read more about Iranian Ajax Security Team Conducts Espionage on U.S. Defense Contractors - Public
Iranian FLYING KITTEN Targets U.S. Defense and Dissidents
CrowdStrike Intelligence tracked FLYING KITTEN — also known as Ajax Security Team — from mid-January 2014, identifying a combination of credential theft and malware delivery targeting multiple US-based defense contractors and political dissidents. The actor registered spoofed domains mimicking target organizations and hosted fake login pages to harvest credentials. After victims entered their credentials, they were redirected to a page prompting them to download a "Browser Patch" — which was actually the Stealer malware (PDB path: Stealer\obj\x86\Release\Stealer.pdb). Stealer exfiltrated captured data to an FTP server. The group also operated parmanpower[.]com, a fake recruiting website registered under the same email (info@usa.gov.us) as other FLYING KITTEN domains, likely used for broader credential collection. Earlier in 2014, FLYING KITTEN used a spoofed IEEE Aerospace Conference website (aeroconf2014[.]org) in the same manner. Attribution was aided by an operational security mistake: domains were initially registered under keyvan.ajaxtm@gmail.com, a Gmail address directly linking the operation to the Iran-based Ajax Security Team, before being updated to the usa.gov.us registrant email. CrowdStrike released YARA rules for both the Stealer RAT and the Flying Kitten installer (IntelRapidStart.exe) to assist in detection.
read more about Iranian FLYING KITTEN Targets U.S. Defense and Dissidents - Public
Shamoon Malware Targets Systems for Data Destruction
The report details a malware resembling the infamous wiper used in the 2012 Iranian cyber incidents, though it's identified as a copycat rather than the original. It destroys data by wiping the Master Boot Record (MBR) using a signed disk driver. The malware encrypts its resources to avoid detection and collects information about potentially important files on infected systems for targeted destruction. Despite similarities to past cyberattacks, its use of different service names and wiping patterns, along with the lack of financial motives, suggests the involvement of "script kiddies" rather than sophisticated cybercriminals. The exact origin or purpose, including targeted countries or sectors, remains unspecified.
read more about Shamoon Malware Targets Systems for Data Destruction - Public
Mahdi (Madi) Malware Campaign Targets Middle Eastern Governments and Infrastructure
Seculert researchers uncovered a sustained spear-phishing campaign dubbed Mahdi, which relied on malicious Word document attachments delivering a simple malware dropper alongside decoy content related to Iran–Israel electronic warfare. The malware communicated with command-and-control servers using disguised, Google-like web pages, with payload modules Base64-encoded inside HTML. Analysis revealed Farsi language artifacts and Persian calendar dates, suggesting an Iranian nexus. Variants were active from at least December 2011, initially hosted in Iran and later in Canada. The campaign targeted critical infrastructure companies, financial services, and government embassies across Iran, Israel, and other Middle Eastern countries, compromising more than 800 victims over eight months.
read more about Mahdi (Madi) Malware Campaign Targets Middle Eastern Governments and Infrastructure - Public
Madi Espionage Campaign Targets Middle Eastern Governments and Critical Sectors
The Madi campaign is a long-running cyber espionage operation that has been active for nearly a year, targeting individuals and organizations primarily across Iran, Israel, Afghanistan, and other countries worldwide. The attackers relied on basic but effective social engineering techniques, including spearphishing emails with malicious PowerPoint slide shows and executables disguised using Right-to-Left Override (RTLO) filenames. Once executed, the Delphi-based malware enabled extensive surveillance through keylogging, screenshot capture, audio recording, and large-scale data theft. Victims included government agencies, critical infrastructure engineering firms, financial institutions, academia, and selected individuals whose communications were monitored over extended periods.
read more about Madi Espionage Campaign Targets Middle Eastern Governments and Critical Sectors - Public
Madi Trojan Campaign Uses Social Engineering to Target Energy and Government Sectors
Symantec Security Response has identified Madi, a Trojan used in targeted social engineering campaigns observed since December 2011. The attacks relied on phishing emails carrying malicious PowerPoint attachments that prompted victims to manually execute an embedded file. Once installed, Trojan.Madi enabled information theft, including keylogging, and supported self-updating capabilities. The malware communicated with command-and-control servers hosted primarily in Iran and later Azerbaijan. Targets spanned multiple sectors, including oil and energy companies, government agencies, a foreign consulate, and US-based think tanks. While victims were concentrated in Middle Eastern countries such as Iran, Israel, and Saudi Arabia, infections were also observed globally, from the United States to New Zealand. The campaign relied entirely on social engineering rather than exploits or zero-day vulnerabilities.
read more about Madi Trojan Campaign Uses Social Engineering to Target Energy and Government Sectors