Threats Feed
- Public
TA450 Shifts Tactics in Latest Phishing Campaign Targeting Israeli Sectors
The Iran-aligned threat actor TA450, also known as MuddyWater, has launched a phishing campaign targeting Israeli employees in global manufacturing, technology, and information security sectors. Using pay-related social engineering lures, the campaign, active since early March 2024, features emails with PDF attachments containing malicious links. These links lead to the download of a ZIP file that installs AteraAgent, a piece of remote administration software abused by TA450. This campaign marks a shift in TA450's tactics, notably using PDF attachments for malicious link delivery and compromised Israeli email accounts matching the lure content, highlighting an increased risk for targeted multinational companies.
read more about TA450 Shifts Tactics in Latest Phishing Campaign Targeting Israeli Sectors - Public
State-Sponsored Cyberattacks Target Israeli Academia and Government Sectors
Recent cyberattacks by state-sponsored groups have targeted Israeli organizations in academia, local government, and managed service providers (MSPs). These attacks aim to cause substantial damage by erasing critical data from servers and workstations using Microsoft's SDelete tool from the SYSInternals suite. The attackers leverage outdated VPN servers to gain initial access, followed by lateral movements within networks to reach their targets. Several organizations have already been impacted, predominantly through an attack on the supply chain, hindering data restoration efforts.
read more about State-Sponsored Cyberattacks Target Israeli Academia and Government Sectors - Public
Lord Nemesis Targets Israeli Academia in Sophisticated Supply Chain Attack
The Iranian hacktivist group Lord Nemesis, also known as 'Nemesis Kitten,' targeted the Israeli academic sector via a supply chain attack on Rashim Software, a provider of academic administration and training software. They breached Rashim's infrastructure and accessed its clients, including numerous academic institutions, by using stolen credentials and exploiting admin accounts on customer systems. This allowed them to extract sensitive data, circumvent multi-factor authentication, and instill fear by releasing findings and sending ominous warnings. The attack highlights the significant risks posed by third-party vendors and demonstrates the group's sophisticated planning and understanding of targeted IT environments.
read more about Lord Nemesis Targets Israeli Academia in Sophisticated Supply Chain Attack - Public
MuddyWater's Covert Phishing Campaign Targets Israeli Government Sectors
In March 2024, the National Cyber Directorate of Israel detected a sophisticated phishing campaign attributed to the Iranian group MuddyWater. This campaign, primarily targeting government and local government sectors in Israel, employs phishing emails with links to malicious ZIP files hosted on Onehub. These files contain the ScreenConnect tool, which enables remote control over compromised computers, allowing for sustained network access. MuddyWater is known for its expertise in social engineering and exploiting vulnerabilities, actively targeting sectors like aviation, academia, communications, government, and energy. Their focus is on maintaining a stealthy presence to facilitate further malicious activities.
read more about MuddyWater's Covert Phishing Campaign Targets Israeli Government Sectors - Public
Mint Sandstorm's Strategic Phishing Tactics and Persistent Threats to Research Organizations
The Mint Sandstorm campaign exhibited sophisticated cyberattack tactics targeting universities and research organizations. Notably, the campaign utilized compromised email accounts for phishing, leveraging social engineering by impersonating high-profile individuals, such as journalists. Initial emails were benign, building trust before delivering malicious content. The attacks involved using the curl command for connecting to a C2 server, downloading malicious files, and deploying custom backdoors like MediaPl and MischiefTut. MediaPl disguised as Windows Media Player, encrypted communications, and used unique persistence methods. The attackers aimed to exfiltrate data and maintain long-term access to compromised systems, posing significant risks to the confidentiality and reputation of the targeted organizations.
read more about Mint Sandstorm's Strategic Phishing Tactics and Persistent Threats to Research Organizations - Public
Homeland Justice Wiper Attack Targets Albanian Telecoms and Government
The Iranian psychological operation group "Homeland Justice" launched a destructive cyberattack targeting Albanian organizations on December 24, 2023. Utilizing a "No-justice" wiper, the group attacked telecom, airline, and government sectors, including ONE Albania, Eagle Mobile Albania, Air Albania, and the Albanian parliament. The attacks were facilitated by malware delivered through PowerShell scripts and executables, employing tools like Plink, RevSocks, and the W2K Res Kit for lateral movement and system manipulation. The campaign, which included methods to give malware an appearance of legitimacy, threatens to extend beyond Albania, indicating a broader geopolitical motive.
read more about Homeland Justice Wiper Attack Targets Albanian Telecoms and Government - Public
Analysis of Homeland Justice's Cyberattack on Albanian Government Infrastructure
Homeland Justice, a politically motivated group emerging in mid-2022, has been linked to cyber attacks targeting the Albanian government and related entities. The group employs tactics such as the deployment of PowerShell scripts and .EXE files, with the former managing connectivity and remote operations and the latter potentially wiping host machine disks. Technical analysis of the payloads revealed sophisticated methods including remote execution, credential exploitation, and data destruction. These actions highlight the group's focus on disrupting Albanian government operations and exposing alleged corruption, signaling significant cyber threats to governmental sectors.
read more about Analysis of Homeland Justice's Cyberattack on Albanian Government Infrastructure - Public
Haghjoyan Group's Cyber Offensive: Data Leaks, Defacement, and Infrastructure Attacks
The Haghjoyan hacker group, self-proclaimed as Iran's cyber army, has emerged during the Israel-Hamas conflict, openly aligning themselves with Iran and diverging from the typical secrecy of cyber warfare groups. Their operations include data leaks and sales, particularly targeting US military personnel's information for Bitcoin. They have conducted website defacement attacks for disruption and propaganda, indicating a geopolitical alignment with Russia. Haghjoyan has claimed responsibility for several significant cyberattacks, such as targeting Israeli Red Alert Emergency Response System, VNC systems controlling Israeli infrastructure, and infecting Israeli computer users with malware. They also targeted surveillance systems, showcasing a strategic approach to cyber warfare.
read more about Haghjoyan Group's Cyber Offensive: Data Leaks, Defacement, and Infrastructure Attacks - Public
Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation
In December, an Iranian attack group launched a phishing campaign impersonating F5 company to target Israeli economic sectors. The campaign aimed for destructive attacks and information gathering. It involved emails from a spoofed F5 address, containing links to download Wiper and Infostealer malware. The attack exploited an F5 critical warning, requiring users to run a Shell Script file. Malicious files included a .NET-based f5updater.exe for Windows and a Bash Script for Linux. These scripts, effective only with administrative privileges, were designed for data destruction and information stealing, with the latter employing advanced evasion techniques like AV service disabling and script obfuscation.
read more about Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation - Public
Peach Sandstorm's FalseFont Backdoor Targets Defense Industrial Base
The Iranian nation-state actor Peach Sandstorm has been observed by Microsoft deploying a new backdoor, FalseFont, targeting individuals in the Defense Industrial Base (DIB) sector. FalseFont is a sophisticated tool with capabilities for remote access, launching files, and data exfiltration to C2 servers. Initially used in early November 2023, its deployment marks a continuation of Peach Sandstorm's evolving cyber tradecraft.
read more about Peach Sandstorm's FalseFont Backdoor Targets Defense Industrial Base - Public
Cyber Toufan: A New Threat in Cyber Warfare Targeting Israeli Entities
Cyber Toufan, a newly emerged cyber group, has been conducting aggressive cyberattacks against Israeli organizations, aligning with regional geopolitical tensions. Their operations include extensive data breaches, extracting sensitive personal and business information, and targeting high-value entities like security firms, government agencies, and commercial businesses. The group also engages in psychological warfare and propaganda. Reports suggest coordination with other hacker groups and a potential link to state sponsorship, likely Iran. This suspicion is supported by similarities in tactics between Cyber Toufan and other Iran-linked groups. The group's activities signify a sophisticated level of cyber warfare and geopolitical strategy.
read more about Cyber Toufan: A New Threat in Cyber Warfare Targeting Israeli Entities - Public
Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns
The Menorah malware, used by the APT34 threat group to target organisations in the Middle East, creates a mutex to ensure single-instance operation. The malware exfiltrates data and executes commands from a hardcoded command and control (C2) server. These commands include creating processes, listing files, downloading files and exfiltrating arbitrary data. The analysis provides technical details, including SHA256 hashes, mutex identifiers and the address of the C2 server, to aid detection and response efforts.
read more about Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns - Public
Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs
ESET researchers identified a series of downloaders used by the OilRig group in campaigns against Israeli targets throughout 2022 and 2023. These downloaders, named SampleCheck5000 (SC5k v1-v3), OilCheck, ODAgent, and OilBooster, utilize legitimate cloud service APIs such as Microsoft Graph OneDrive, Outlook, and Office Exchange Web Services for command and control (C&C) communication and data exfiltration. Sharing a common OilRig-operated account, these downloaders enable the exchange of messages, commands, and data uploads between victims and operators. Notably, the same account is often used by multiple victims. The tools are part of OilRig's ongoing efforts to re-compromise persistently targeted entities in Israel, including a manufacturing company, a governmental organization, and a healthcare entity. The use of cloud services helps the downloaders blend into regular network traffic, making detection more challenging.
read more about Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs - Public
Iranian-Backed Polonium Group Targets Israeli Critical Infrastructure
The Polonium attack group, associated with the Lebanese faction and the Iranian Ministry of Intelligence, is actively targeting sectors in Israel, namely water, energy, and IT. This group's primary focus is on cyber espionage (CNE), with a recent shift towards potentially destructive activities (CNA). Their strategy involves exploiting known vulnerabilities (N-Day) and leveraging public VPN and cloud services, particularly PCloud, for communication and control. Despite these efforts, significant breaches in Israeli systems have not been confirmed. An alert highlights the risk of exploiting vulnerabilities in Fortinet equipment, underlining the need for enhanced cyber defense measures in the targeted sectors.
read more about Iranian-Backed Polonium Group Targets Israeli Critical Infrastructure - Public
IRGC Cyber Campaigns Against U.S. and Israeli Critical Infrastructure
Iranian IRGC-affiliated cyber actors, using the persona “CyberAv3ngers,” have been actively targeting and compromising Unitronics Vision Series programmable logic controllers (PLCs) used in the Water and Wastewater Systems (WWS) Sector across multiple U.S. states. These attacks, observed since at least November 2023, involve compromising default credentials and defacing the PLCs, potentially rendering them inoperative. The actors also targeted Israeli PLCs in various sectors like water, energy, and distribution. Additionally, they falsely claimed responsibility for cyberattacks on critical infrastructure in Israel and have connections to the Soldiers of Solomon group. The attacks leverage internet-facing applications and involve tactics like data destruction, resource hijacking, and potential use of ransomware.
read more about IRGC Cyber Campaigns Against U.S. and Israeli Critical Infrastructure - Public
Phishing Campaign Targets Albanian Government with Microsoft Exchange Vulnerability
A phishing malware campaign targeting Albanian governmental entities was discovered, involving an archived file named "kurs trajnimi.zip." The malware uses "ScreenConnectWindowsClient.exe" for command-and-control (C2) operations, exploiting CVE-2023-36778, a Microsoft Exchange Server vulnerability. Static analysis revealed techniques for screen capture, anti-analysis, and system discovery. The malicious program requires Administrator or SuperUser privileges to execute, indicating an intent to evade detection and exploit higher-level system resources.
read more about Phishing Campaign Targets Albanian Government with Microsoft Exchange Vulnerability - Public
BiBi Wiper: A Politically Charged Cyberattack Targets Israeli Defense and Data Sectors
In October, a significant cyberattack targeted Israel, affecting defense contractors and a data-hosting company. This operation, known as "Mission: Data Destruction," employed a new data-wiping malware, BiBi-Linux, with a Windows variant called bibi.exe, to cause extensive data loss. The hacktivist group Karma, linked to these attacks, used this campaign to express political dissent against Israeli Prime Minister Benjamin Netanyahu. These incidents were part of a larger trend of hacktivist groups using data destruction methods, with similar tactics observed in other groups like the Iranian-linked APT, Moses Staff. The campaign involved manual data deletion and spreading malware within networks.
read more about BiBi Wiper: A Politically Charged Cyberattack Targets Israeli Defense and Data Sectors - Public
Imperial Kitten's Middle East Cyber Campaign: Transport and Tech Sectors Targeted
CrowdStrike's investigation into Imperial Kitten's cyber activities reveals targeted cyberattacks and strategic web compromise (SWC) operations against transportation, logistics, and technology sectors, primarily in the Middle East. These attacks, spanning from early 2022 to 2023, involved the use of compromised websites, phishing, and malware like IMAPLoader and StandardKeyboard for initial access and persistence. Techniques such as SQL injection, the use of public exploits, and credential theft were employed. The operations leveraged tools like PAExec and NetScan for lateral movement and credential harvesting. IMPERIAL KITTEN also used custom malware and open-source tools for data exfiltration, with some utilizing Discord for command and control communications.
read more about Imperial Kitten's Middle East Cyber Campaign: Transport and Tech Sectors Targeted - Public
Agonizing Serpens APT Targets Israeli Education and Tech Sectors in Sophisticated Cyberattacks
The Agonizing Serpens APT group conducted a series of cyberattacks on Israel's education and technology sectors from January to October 2023. These attacks involved stealing sensitive data, including personal and intellectual property, followed by deploying various wipers like MultiLayer, PartialWasher, and BFG Agonizer to erase traces and disable endpoints. Techniques used included exploiting web servers, deploying web shells, network scanning with Nbtscan and WinEggDrop, credential theft via Mimikatz, and data exfiltration using tools like WinSCP. The group's upgraded capabilities aimed to bypass endpoint detection and response (EDR) systems, employing a mix of known and custom tools for evasion.
read more about Agonizing Serpens APT Targets Israeli Education and Tech Sectors in Sophisticated Cyberattacks - Public
BiBi-Linux Wiper: New Malware Targets Israeli Companies Amidst Conflict
The Security Joes team discovered a new Linux Wiper malware, dubbed BiBi-Linux Wiper, used by a pro-Hamas hacktivist group during the conflict between Israel and Hamas. This malware, an x64 ELF executable, is designed to destroy systems by overwriting and renaming files, particularly targeting Israeli companies. It lacks obfuscation, utilizes multi-threading for efficiency, and avoids corruption of certain file types crucial for its operation. The term "BiBi" in the malware's naming convention is a political reference to Israeli Prime Minister Benjamin Netanyahu, suggesting a targeted political motive behind the attacks.
read more about BiBi-Linux Wiper: New Malware Targets Israeli Companies Amidst Conflict - Public
Yellow Liderc's Multi-Faceted Cyber Campaign Targets Global Industries
Yellow Liderc, a persistent threat actor, has been actively targeting industries including maritime, shipping and logistics in the Mediterranean, as well as aerospace, defense, and IT managed service providers in the US, Europe, and the Middle East. Their recent activities involve strategic web compromises to fingerprint website visitors and deploy a new .NET malware, IMAPLoader. This malware uses email for command and control and delivers additional payloads. It employs 'AppDomain Manager Injection' for execution. Concurrent phishing campaigns distribute a malicious Excel file containing a basic Python backdoor. The focus remains heavily on the maritime, shipping, and logistics sectors.
read more about Yellow Liderc's Multi-Faceted Cyber Campaign Targets Global Industries - Public
Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack
Crambus launched a sophisticated attack involving multiple malware strains, including three new ones: Tokel, Dirps, and Infostealer.Clipog, along with the known PowerExchange backdoor. The malware provided a wide range of functionalities from executing arbitrary PowerShell commands to information stealing and email monitoring. Living-off-the-land tools like Mimikatz and Plink were also deployed to dump credentials and configure port-forwarding for RDP access, respectively. The attackers displayed an advanced level of evasion, execution, and command-and-control techniques. The malicious activities spanned over several months, indicating a well-coordinated and persistent attack strategy.
read more about Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack - Public
APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia
Trend Micro researchers identified APT34 using a new custom backdoor named Menorah — a .NET-based malware delivered via a malicious Word document ("MyCv.doc") disguised as a Seychelles government license registration form. The document contained hidden macros that dropped Menorah into the system's %ALLUSERSPROFILE%\Office365 directory and established persistence through a scheduled task named "OneDriveStandaloneUpdater." Once installed, Menorah fingerprinted the victim machine using a hashed combination of machine name and username, communicated with a remote C2 server over HTTP using Base64-encoded, XOR-obfuscated traffic, and supported commands for file listing, selective file upload, shell command execution, and file download. The pricing in the lure document was denominated in Saudi Riyal, strongly suggesting the targeted victim was an organization in Saudi Arabia. Trend Micro noted functional similarities to APT34's earlier SideTwist backdoor, particularly in C2 communication and machine fingerprinting logic, though Menorah is a .NET reimplementation with enhanced sandbox evasion and traffic obfuscation.
read more about APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia - Public
OilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive
ESET's September 2023 report analyzes two OilRig (APT34/Lyceum) cyberespionage campaigns that exclusively targeted Israeli organizations: Outer Space (2021) and Juicy Mix (2022). Both campaigns followed the same playbook — OilRig compromised legitimate Israeli websites to serve as C2 servers, then used VBS droppers (likely distributed via spearphishing) to install custom C#/.NET backdoors. In Outer Space, the backdoor was Solar, deployed against an Israeli human resources company; in Juicy Mix, the upgraded Mango backdoor was deployed against a healthcare organization, using a compromised Israeli job portal as C2. Solar is a basic XOR-encrypted backdoor supporting file operations, command execution, and automated data staging. Mango is a more capable successor that adds TLS encryption, native API usage (CreateProcess via DllImport), symbol name obfuscation, and string stacking. Post-compromise tooling included SC5k (a downloader using Microsoft Exchange Web Services draft emails for covert C2), CDumper and EDumper (Chrome and Edge browser credential and cookie stealers), IDumper (a PowerShell-based Windows Credential Manager stealer), and MKG (a C/C++ Chrome data dumper reused from earlier OilRig campaigns). A Mango v1.1.1 variant uploaded to VirusTotal in July 2023 under the name Menorah.exe was also identified, using tecforsc-001-site1.gtempurl[.]com as its C2. ESET notified the Israeli national CERT about all compromised websites identified in the research.
read more about OilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive