Latest Update27/08/2026

Threats Feed

  1. Public

    Charming Kitten Targets Global Sectors with Sponsor Backdoor

    Charming Kitten, an Iran nexus threat actor group, used the Sponsor backdoor to target 34 entities across Brazil, Israel, and UAE. Initial access was gained by exploiting Microsoft Exchange vulnerabilities (CVE-2021-26855). The campaign targeted various sectors, including automotive, communications, engineering, financial services, healthcare, insurance, legal, manufacturing, retail, technology, and telecommunications. Sponsor backdoor, disguised as an updater program, used discreetly deployed batch files to evade detection. Charming Kitten also deployed tools like Plink, Merlin agent, Mimikatz, and Meterpreter reverse shells.

    read more about Charming Kitten Targets Global Sectors with Sponsor Backdoor
  2. Public

    Peach Sandstorm’s Multi-Faceted Attacks on Satellite, Defense, and Pharma Sectors

    Peach Sandstorm, an Iranian threat actor, has conducted password spray attacks since February 2023 against global organizations, notably in the satellite, defense, and pharmaceutical sectors. These attacks originated from TOR IPs and employed a mix of public and custom tools like AzureHound and Roadtools for reconnaissance. Once inside the network, the group established persistence through mechanisms like Azure subscriptions and Azure Arc. They also attempted to exploit vulnerabilities in Zoho ManageEngine and Confluence. Some instances involved data exfiltration and lateral movement using techniques like Golden SAML and remote desktop protocol (RDP).

    read more about Peach Sandstorm’s Multi-Faceted Attacks on Satellite, Defense, and Pharma Sectors
  3. Public

    Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide

    Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.

    read more about Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide
  4. Public

    Ballistic Bobcat Exploits Microsoft Exchange Vulnerabilities to Compromise 34 Organizations

    The Ballistic Bobcat (aka Charming Kitten) threat group exploited known vulnerabilities in Microsoft Exchange servers, particularly CVE-2021-26855, to gain initial access to 34 organizations, primarily located in Israel. The group employed a backdoor known as Sponsor and relied on a modular approach that used both configuration files and batch files to evade detection. Besides, the group utilized a range of open-source tools for various activities, including tunneling and credential dumping. The victims are from diverse sectors but are mainly opportunistic rather than specifically targeted. Two victims were identified outside Israel, in Brazil and the UAE, linked to healthcare and an unidentified organization.

    read more about Ballistic Bobcat Exploits Microsoft Exchange Vulnerabilities to Compromise 34 Organizations
  5. Public

    Iranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack

    The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Cyber National Mission Force (CNMF) identified multiple APT actors exploiting vulnerabilities in an Aeronautical Sector organization as early as January 2023. The actors targeted a public-facing application (Zoho ManageEngine ServiceDesk Plus) and the organization’s firewall device, exploiting CVE-2022-47966 and CVE-2022-42475. They gained unauthorized access, established persistence, moved laterally, and engaged in defense evasion by deleting logs. Although the attackers achieved extensive network enumeration and credential access, the report didn't confirm any data exfiltration.

    read more about Iranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack
  6. Public

    APT34 Targets U.S. Enterprises with New SideTwist Trojan Variant

    APT34 has launched a new phishing campaign, using a decoy file named “GGMS Overview.doc” to target U.S.-based enterprises. The campaign employs a variant of the SideTwist Trojan for long-term control over victim hosts. Malicious macros in the document deploy the Trojan, which communicates with a C&C server. Interestingly, the C&C IP address is associated with the United States Department of Defense Network Information Center. The Trojan is capable of executing commands from the C&C and exfiltrating local files. It suggests the APT34 group might be conducting a test operation to preserve attack resources.

    read more about APT34 Targets U.S. Enterprises with New SideTwist Trojan Variant
  7. Public

    APT35's Exploitation of Microsoft Exchange: Targeting Europe, Middle East, and North America

    AttackIQ's August 2023 report profiles APT35 (also known as Charming Kitten and Phosphorus), an Iranian state-sponsored espionage group active since at least 2014. The report presents an attack graph emulating APT35's December 2021 exploitation of Microsoft Exchange ProxyShell vulnerabilities — CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 — to gain initial access across targets in Europe, the Middle East, and North America. The documented attack chain begins with web shell deployment on the compromised Exchange server, followed by scheduled task persistence, disabling of Microsoft Defender via registry modification, WDigest authentication enablement for plaintext credential capture, LSASS memory dumping via rundll32.exe and comsvcs.dll, and data exfiltration via HTTP POST requests. The group also created local accounts added to the Administrators and Remote Desktop Users groups and opened port 3389 (RDP) through Windows Firewall for persistent remote access. APT35 targets government entities, academic institutions, media organizations, defense, energy, engineering, business services, and telecommunications sectors, with a particular focus on the United States and Middle East.

    read more about APT35's Exploitation of Microsoft Exchange: Targeting Europe, Middle East, and North America
  8. Public

    German Authorities Warn of Charming Kitten Cyberespionage Against Exiled Iranians

    Charming Kitten has intensified its cyber espionage operations targeting Iranian dissidents, legal professionals, journalists, and human rights activists in Germany and abroad. According to the German BfV, the group uses detailed social engineering and spoofed online identities to initiate contact and build trust. Victims are lured into video calls via phishing links that mimic legitimate platforms like Google or Microsoft. These links lead to credential-harvesting sites, often intercepting two-factor authentication as well. Stolen credentials are then used to access cloud services and extract personal data using tools like Google Takeout.

    read more about German Authorities Warn of Charming Kitten Cyberespionage Against Exiled Iranians
  9. Public

    TA453 Campaign Deploys Novel PowerShell Backdoor and Mac-Specific Malware

    In mid-May 2023, threat actor TA453 targeted a US-based nuclear security expert affiliated with a foreign affairs think tank using deceptive emails. After initial contact, TA453 deployed a novel PowerShell backdoor, GorjolEcho, via cloud hosting providers. Upon realizing the target used a Mac, they sent another malicious email that delivered Mac-specific malware, NokNok. TA453 operates in support of Iran's Islamic Revolutionary Guard Corps (IRGC), specifically focusing on entities and individuals in the foreign affairs sector, particularly those dealing with Middle Eastern affairs and nuclear security.

    read more about TA453 Campaign Deploys Novel PowerShell Backdoor and Mac-Specific Malware
  10. Public

    MuddyWater Upgrades: The Emergence of PhonyC2 Framework

    Deep Instinct's research team has uncovered a new Command and Control (C2) framework named PhonyC2, which is believed to be linked to the threat group MuddyWater. The PhonyC2 framework was found on a server connected to infrastructure previously used by MuddyWater in various cyberattacks, including the assault on Technion in Israel. This discovery suggests PhonyC2 is MuddyWater's latest tool for orchestrating cyber espionage and it's used in an active PaperCut exploitation. The code analysis revealed structural and functional similarities to MuddyWater's previous C2 frameworks (MuddyC3), reinforcing the attribution.

    read more about MuddyWater Upgrades: The Emergence of PhonyC2 Framework
  11. Public

    Decoding Charming Kitten's POWERSTAR Deployment in Recent Cyber Attack

    The Iranian cyber-espionage group, Charming Kitten, targeted an individual who published an article about Iran. The attackers impersonated a reporter and carried out a series of seemingly benign interactions before sending a malicious RAR file containing the POWERSTAR backdoor. The backdoor, once executed, collects system information and communicates with a command-and-control server via encrypted channels. The attackers employ several modules for system reconnaissance, establishing persistence, and cleaning up forensic evidence. Notably, they leveraged the InterPlanetary File System (IPFS) as a fallback mechanism for command-and-control communication.

    read more about Decoding Charming Kitten's POWERSTAR Deployment in Recent Cyber Attack
  12. Public

    PowerExchange Campaign: APT34's Persistent Threat to UAE Government

    The PowerExchange campaign, attributed to APT34, targeted Microsoft Exchange servers of a UAE government entity using a PowerShell backdoor. Delivered via phishing emails, the backdoor used the MicrosoftEdgeUpdateService for persistence, enabling frequent execution. The attackers used the Exchange Web Services API for command-and-control, deploying further payloads like Invoke-TheHash modules for lateral movement and webshells for credential harvesting.

    read more about PowerExchange Campaign: APT34's Persistent Threat to UAE Government
  13. Public

    APT34 Suspected in Coordinated Attack on UAE Government Infrastructure

    FortiEDR's research lab discovered a series of attacks on a government entity in the United Arab Emirates. The attacks involved a novel PowerShell-based backdoor dubbed PowerExchange. The backdoor's command and control (C2) protocol used the victim's Exchange server for communication. Further investigations revealed additional implants and a new web shell named ExchangeLeech that could harvest credentials. Iranian threat actor APT34 is suspected to be behind the attacks, which involved phishing emails for initial access, lateral movement within the network, and using scheduled tasks for persistence.

    read more about APT34 Suspected in Coordinated Attack on UAE Government Infrastructure
  14. Public

    WINTAPIX: New Kernel Driver Targets Middle Eastern Countries

    Fortinet researchers discovered WINTAPIX, a sophisticated Windows kernel driver suspected to be the work of Iranian threat actors, targeting IIS web servers across the Middle East — primarily in Saudi Arabia, with additional targeting of Jordan, Qatar, and the United Arab Emirates. Active since at least mid-2020, the malware remained largely undetected for years before significant spikes in activity emerged in August–September 2022 and February–March 2023. WINTAPIX operates at the kernel level, giving it deep system access and making it significantly harder to detect and remove than user-mode implants. The driver uses the open-source Donut framework to generate and inject shellcode that loads an obfuscated .NET payload into a target process. The payload — protected with SmartAssembly and Eazfuscator to resist reverse engineering — provides the operators with backdoor access and proxy functionality, enabling persistent remote control and traffic tunneling through the compromised IIS server. The driver itself is shielded with VMProtect, transforming its code into a virtualized format to hinder static analysis.

    read more about WINTAPIX: New Kernel Driver Targets Middle Eastern Countries
  15. Public

    Iranian APTs Exploit PaperCut Vulnerability in Global Cyber Attacks

    On May 5–8, 2023, Microsoft Threat Intelligence reported that two Iranian state-backed groups had joined an ongoing wave of attacks targeting CVE-2023-27350, a pre-authentication critical remote code execution vulnerability (CVSS 9.8) in PaperCut MF and NG print management software versions 8.0 and later. The two groups are Mango Sandstorm (also known as Mercury or MuddyWater, linked to Iran's Ministry of Intelligence and Security/MOIS) and Mint Sandstorm (also known as Phosphorus or APT35, linked to Iran's Islamic Revolutionary Guard Corps/IRGC). Mint Sandstorm's exploitation was characterized as opportunistic, targeting organizations across multiple sectors and geographies without specific victim selection. Mango Sandstorm's activity was lower-volume, with operators reusing tools from prior intrusions to connect to existing C2 infrastructure — indicating the group was extending rather than initiating campaigns. The vulnerability had been disclosed in March 2023; public PoC exploits were released shortly after, enabling rapid threat actor adoption. Earlier exploitation was attributed to Lace Tempest (linked to Clop ransomware) and separately led to LockBit ransomware deployments. CISA added CVE-2023-27350 to its Known Exploited Vulnerabilities catalog on April 21, 2023, mandating federal agencies patch by May 12. VulnCheck subsequently documented a new exploitation method that bypassed existing detections, highlighting the difficulty of detection-only defenses. PaperCut is used by over 100 million users at 70,000+ organizations including large enterprises, government bodies, and educational institutions globally. Patched versions are 20.1.7, 21.2.11, and 22.0.9 and later.

    read more about Iranian APTs Exploit PaperCut Vulnerability in Global Cyber Attacks
  16. Public

    Unveiling BellaCiao: Charming Kitten's Sophisticated Malware Tailored For Individuals

    Charming Kitten group's latest malware, BellaCiao, targets Microsoft Exchange servers across the United States, Europe, the Middle East (Turkey), and India. The malware uses a unique communication approach with its command-and-control infrastructure and is tailored to suit individual targets. BellaCiao is a dropper malware that delivers other payloads based on instructions from the C2 server. The initial infection vector is suspected to be Microsoft Exchange exploit chains, and the malware establishes persistence by masquerading as legitimate Microsoft Exchange server processes.

    read more about Unveiling BellaCiao: Charming Kitten's Sophisticated Malware Tailored For Individuals
  17. Public

    Educated Manticore Targets Israel with Improved Cyber Arsenal

    Educated Manticore, an Iranian-aligned threat actor linked to the Phosphorus group, has been found targeting Israel with an improved arsenal of tools. The group adopts recent trends, using ISO images and other archive files to initiate infection chains. They have significantly enhanced their toolset with techniques such as .NET executables constructed as Mixed Mode Assembly. The final payload is an updated version of the implant PowerLess, previously attributed to Phosphorus ransomware operations. This evolution shows the group's continuous refinement of their toolsets and delivery mechanisms.

    read more about Educated Manticore Targets Israel with Improved Cyber Arsenal
  18. Public

    Mint Sandstorm Subgroup Targets US Critical Infrastructure

    The report details the Mint Sandstorm subgroup's cyberattacks targeting US critical infrastructure, including seaports, energy companies, transit systems, and a major utility and gas entity. The group rapidly adopted publicly disclosed proof-of-concept (POC) code to exploit vulnerabilities in internet-facing applications. The attacks also involved custom tools and implants, lateral movement, and persistence techniques. The phishing campaigns targeted individuals affiliated with think tanks and universities in Israel, North America, and Europe. The targeted sectors include transportation, energy, utilities, policy, security, and academia.

    read more about Mint Sandstorm Subgroup Targets US Critical Infrastructure
  19. Public

    MuddyWater APT Uses Legitimate Remote Management Tool for Persistence

    Group-IB's April 2023 report documents MuddyWater's use of SimpleHelp, a legitimate remote device management tool, as a persistence mechanism on victim devices. Group-IB identified this technique in fall 2022 through retrospective analysis of MuddyWater infrastructure using their Threat Intelligence platform. SimpleHelp is not compromised — the threat actors download it directly from the official website and deploy it to maintain persistent, stealthy remote access to victim systems. The SimpleHelp client runs as a system service, surviving reboots and enabling operators to connect at any time, execute commands with administrator privileges, and perform covert terminal access. As of publication, at least eight MuddyWater servers had SimpleHelp installed. Group-IB also uncovered previously unknown MuddyWater infrastructure by tracking three unique HTTP ETag hashes (2aa6-5c939a3a79153, 2aa6-5b27e6e58988b, 2aa6-5c939a773f7a2) consistent across the group's VPS fleet, linking 63 IP addresses to MuddyWater activity. One incident response case in fall 2022 at a Middle Eastern organization confirmed active use of 164.132.237.65 — a server that also hosted Cobalt Strike with a custom, watermark-free configuration file. A shortcut LNK file linked to IP 91.121.240.108 targeted a UAE Ministry of Health and Prevention lure (mohap.gov.ae). An additional PowerShell backdoor script linked to 91.121.240.96 was uploaded to VirusTotal from Kazakhstan. The distribution method for SimpleHelp is unconfirmed but likely involves phishing emails with links to OneDrive, Onehub, or Dropbox. Post-installation lateral movement likely involves Fast Reverse Proxy (FRP) or Ligolo.

    read more about MuddyWater APT Uses Legitimate Remote Management Tool for Persistence
  20. Public

    MERCURY and DEV-1084's Destructive Cyber Operations Against Cloud and On-Premises Environments

    MERCURY and DEV-1084, associated with the Iranian government, orchestrated a destructive operation targeting on-premises and cloud environments under the guise of a standard ransomware campaign. The attack chain involved exploiting unpatched vulnerabilities for initial access, extensive reconnaissance, persistence establishment, and lateral movement within the network. High-privilege credentials were used to create widespread destruction of resources. The attackers also breached Azure AD environments to cause further damage and data loss. They conducted extensive mailbox operations and sent emails internally and externally impersonating high-ranking employees.

    read more about MERCURY and DEV-1084's Destructive Cyber Operations Against Cloud and On-Premises Environments
  21. Public

    Breaking Down OilRig's August 2022 Attack: A Detailed Look at Techniques Used

    The Iranian state-sponsored threat actor, OilRig, known for targeting global sectors such as Government, Financial Services, Energy, Telecommunications, and Technology, carried out an attack in August 2022 using a malicious Word document. This document contained embedded macros that dropped additional payloads for discovery, collection, and exfiltration routines. The payloads used PowerShell scripts and Windows utilities for information gathering and established persistence with a scheduled task named "WindowsUpdate". OilRig used multiple techniques in this attack such as Process Discovery, System Information Discovery, File and Directory Discovery, System Network Configuration Discovery, and others.

    read more about Breaking Down OilRig's August 2022 Attack: A Detailed Look at Techniques Used
  22. Public

    Cyber Threats on the Rise: APT33 Targets Aerospace, Shipping, and Manufacturing via OneNote

    Loginsoft's March 2023 report examines the broader OneNote malware delivery campaign, within which APT33 is identified as one of several threat actors exploiting Microsoft OneNote files to deliver malware payloads. The campaign emerged after Microsoft disabled malicious macro execution in Office documents, prompting attackers to pivot to OneNote notebooks as a new delivery vehicle. APT33 used this method to target organizations in the aerospace, shipping, and manufacturing sectors, embedding malicious files or URLs within OneNote pages hidden behind counterfeit clickable buttons — tricking victims into triggering payload execution. The malware families associated with the broader campaign include commodity RATs and stealers such as NETWIRE, Quasar RAT, AsyncRAT, XWorm, Formbook, Agent Tesla, RedLine Stealer, IcedID, QakBot, Emotet, and the APT33-linked DOUBLEBACK backdoor. The technique chain involved spearphishing attachment delivery, obfuscated embedded payloads, process injection, and proxy execution via Windows LOLBins including mshta.exe, rundll32.exe, and regsvcs/regasm to evade defenses. Note: the original source URL is no longer accessible; content is reconstructed from the archived feed description and threat record.

    read more about Cyber Threats on the Rise: APT33 Targets Aerospace, Shipping, and Manufacturing via OneNote
  23. Public

    COBALT ILLUSION Impersonates Think Tank Staff to Target Middle Eastern Affairs

    The Secureworks report details a phishing campaign by the Iranian threat group COBALT ILLUSION, which used a fake Atlantic Council employee, "Sara Shokouhi", to target researchers working on human rights in Iran. The campaign used stolen imagery and a fake online presence to build rapport before attempting to steal credentials or deploy malware. This tactic mirrors previous COBALT ILLUSION operations, highlighting the consistent use of sophisticated social engineering and data harvesting techniques to gather intelligence on behalf of the Iranian government. The report provides indicators of compromise (IOCs) to help mitigate further attacks.

    read more about COBALT ILLUSION Impersonates Think Tank Staff to Target Middle Eastern Affairs
  24. Public

    MuddyWater Masquerades as Hacktivists in Combined Extortion and Disinformation Campaign

    Iranian state-sponsored threat actor MuddyWater has aggressively targeted Israeli organizations in the finance, academia, and government sectors since late 2022. Operating under the guise of a hacktivist persona named "Darkbit," the group conducted a combined destructive ransomware and disinformation campaign against an academic institution in February 2023. Gaining access via phishing and exploiting vulnerabilities like Log4j, the attackers deployed custom Go-based ransomware alongside remote access tools like SyncroRAT and PowerShower. The operation involved both computer network exploitation, stealing 4TB of data—and computer network attacks, disrupting critical systems while demanding an exorbitant 80 Bitcoin ransom to mask their state-backed espionage and psychological objectives.

    read more about MuddyWater Masquerades as Hacktivists in Combined Extortion and Disinformation Campaign