Latest Update27/08/2026

Threats Feed

  1. Public

    TA452 Utilizes PowerShell and AutoHotkey in its Intrusion

    TA452's August 2022 intrusion involved a malicious Word document with a VBA macro that established persistence and C2 communication. The threat actors used AutoHotkey for keylogging, PowerShell scripts for discovery, and exfiltrated data using makecab.exe. They employed sophisticated techniques such as base64 encoding, obfuscation, and scheduled tasks to maintain access and evade detection. The campaign is linked to OilRig group and targeted organizations with custom-tailored malware, hinting at state-sponsored activity. Data was exfiltrated over encrypted channels, with evidence pointing to an organized and targeted approach.

    read more about TA452 Utilizes PowerShell and AutoHotkey in its Intrusion
  2. Public

    New APT34 Malware Variant Abuses Exchange Servers for Data Exfiltration

    Trend Micro researchers identified a December 2022 cyberespionage campaign attributed to APT34 targeting government entities in the Middle East. The attack used a custom .NET dropper (Trojan.MSIL.REDCAP.AD) to deploy four components: a malicious Password Filter DLL (psgfilter.dll) registered into the Windows LSA to intercept plaintext credentials on every password change, a backdoor (Backdoor.MSIL.REDCAP.A) that authenticated to victim Exchange Servers using stolen credentials via Exchange Web Services (EWS), configuration files, and the Microsoft Exchange WebServices library. Stolen credentials and files were exfiltrated as email attachments through compromised government mailboxes to six external attacker-controlled addresses at Proton Mail and Gmail. The campaign's novelty lies in combining password filter abuse for persistent credential harvesting with Exchange-based exfiltration over legitimate mail traffic — a technique first observed for APT34. Hardcoded Exchange server domains and attacker email addresses inside the samples, along with code-level overlap with APT34's prior Karkoff and Saitama implants, formed the basis of attribution. Researchers noted evidence of a deep foothold across a government Active Directory forest, suggesting this was one component of a larger ongoing campaign.

    read more about New APT34 Malware Variant Abuses Exchange Servers for Data Exfiltration
  3. Public

    Unmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations

    Secureworks Counter Threat Unit links two separate hacktivist personas — Moses Staff and Abraham's Ax — to a single Iranian threat group tracked as COBALT SAPLING. Moses Staff emerged in September 2021, targeting Israeli companies and individuals tied to Israel's signals intelligence Unit 8200 through data theft, leaks, and destructive encryption using the PyDCrypt loader and DCSrv wiper. Abraham's Ax surfaced in November 2022, pivoting to attack Saudi Arabian government ministries — likely in response to reported Israeli-Saudi normalization efforts that Iran perceived as a regional threat. Secureworks identifies the link through overlapping infrastructure: both groups' leak sites were hosted in near-adjacent IP addresses within the same subnet at early points in their operation, a pattern assessed as highly unlikely to be coincidental. Additional shared indicators include nearly identical logo style, multilingual WordPress-based leak sites both registered through the same Swedish registrar, reused video production elements, and the same ASPX web shells used in intrusions attributed to Moses Staff. The StrifeWater RAT and DriveGuard tool have been linked to COBALT SAPLING through technical overlaps across intrusions. Malware artifacts suggest the group has been active since at least November 2020, predating the Moses Staff persona's public debut by nearly a year.

    read more about Unmasking Abraham's Ax and Moses Staff: A Look at COBALT SAPLING's Operations
  4. Public

    TA453 Phishing Campaign Targets UK Government and Academia

    TA453, also known as Charming Kitten, has targeted sectors such as academia, defence, government, NGOs, think tanks and journalists in the UK and other regions of interest. The group uses spear phishing attacks, using open source reconnaissance to create tailored phishing emails. These emails are often sent from fake social media profiles or compromised email accounts. Once a relationship has been established, TA453 directs victims to malicious links or documents and steals credentials upon interaction. The group also exploits compromised email accounts to steal sensitive data, set up mail forwarding rules and facilitate further surveillance and future attacks.

    read more about TA453 Phishing Campaign Targets UK Government and Academia
  5. Public

    MuddyWater APT: Iran's Cyber Espionage Across the Middle East and Beyond

    MuddyWater, an Iranian state-sponsored APT linked to the Ministry of Intelligence and Security (MOIS), focuses on cyber espionage and IP theft, occasionally using ransomware to disguise its activities. Active since 2017, the group primarily targets the Middle East, including Turkey, Israel, the UAE and Pakistan, with attacks extending to Europe, Asia, Africa and North America. Its targets span the government, defence, healthcare, energy, financial services, and education sectors. Using spear phishing, DNS tunneling and tools such as SimpleHelp, PowerShell and PowGoop, MuddyWater employs credential dumping, lateral movement and persistent remote access. Recent campaigns include phishing attacks against Turkish agencies and Israeli companies.

    read more about MuddyWater APT: Iran's Cyber Espionage Across the Middle East and Beyond
  6. Public

    Broadening Horizons: TA453's New Approaches in Cyber Operations

    Since late 2020, threat actor TA453 has exhibited a shift in targeting and tactics. Previously targeting academics, diplomats, and journalists among others, TA453 has expanded to target medical researchers, aerospace engineers, realtors, and travel agencies. New tactics include the use of compromised accounts, malware, and confrontational lures. Despite this shift, Proofpoint assesses that TA453 operates in support of Iran's IRGC Intelligence Organization, indicating a broadening scope of cyber operations. The operations appear to focus on the US, Israel, and various European countries, targeting sectors like academia, diplomacy, journalism, human rights, and energy.

    read more about Broadening Horizons: TA453's New Approaches in Cyber Operations
  7. Public

    Drokbk Malware: A Tool for COBALT MIRAGE's Cyber Arsenal

    The COBALT MIRAGE threat group is using Drokbk malware to target U.S. local government networks. The malware, written in .NET, consists of a dropper and a payload, with limited built-in functionality, primarily executing additional commands from the command and control (C2) server. The February 2022 intrusion began with a compromise of a VMware Horizon server using two Log4j vulnerabilities. Drokbk is deployed post-intrusion alongside other access mechanisms, such as Fast Reverse Proxy (FRPC) tool, for persistence within the victim's environment.

    read more about Drokbk Malware: A Tool for COBALT MIRAGE's Cyber Arsenal
  8. Public

    Spearphishing and Syncro: The Tools of MuddyWater's Recent Cyber Attacks

    The MuddyWater group has launched a campaign targeting countries including Armenia, Azerbaijan, Egypt, Iraq, Israel, Jordan, Oman, Qatar, Tajikistan, and the UAE. The group has employed the remote administration tool "Syncro" and used spear-phishing techniques, leveraging Dropbox and OneDrive to deliver the malicious Syncro MSI installer. The threat actors also utilized legitimate corporate email accounts to distribute their phishing emails. The sectors notably targeted include the data hosting, hospitality, and insurance sectors.

    read more about Spearphishing and Syncro: The Tools of MuddyWater's Recent Cyber Attacks
  9. Public

    Iranian APTs Exploit Log4Shell to Compromise FCEB Network

    In April 2022, CISA detected Iranian government-sponsored APT activity compromising an FCEB organization's network via the Log4Shell vulnerability. Initial exploitation targeted an unpatched VMware Horizon server, later spreading to the domain controller. The threat actors utilized PowerShell commands, disabled Windows Defender, and established persistence through scheduled tasks. Tools like Mimikatz and Ngrok were deployed for credential harvesting and C2 communication. Despite attempts to dump the LSASS process, additional anti-virus measures thwarted this activity. Lateral movement was observed, as were activities aimed at credential and account manipulation.

    read more about Iranian APTs Exploit Log4Shell to Compromise FCEB Network
  10. Public

    Iranian State-Sponsored Actors Exploit Log4Shell to Target US Government

    In April 2022, Iranian government-sponsored actors exploited the Log4Shell vulnerability in VMware Horizon servers, targeting a Federal Civilian Executive Branch (FCEB) organization. They installed XMRig crypto mining malware and used tools like Mimikatz and Ngrok for credential theft and tunneling. The attack involved disabling Windows Defender, downloading malicious files, hiding artifacts, and creating scheduled tasks for persistence. The campaign highlights advanced tactics in disabling security controls and maintaining persistent access. The targeted sector was the US government.

    read more about Iranian State-Sponsored Actors Exploit Log4Shell to Target US Government
  11. Public

    Charming Kitten's Cyber Arsenal: Tools and Techniques Explained

    The Iranian APT group, Charming Kitten (APT35), targets human rights activities, academia, media organizations, and political entities in the US and Central Eastern countries. Notable attacks include the 2017 HBO hack, which led to leaked unaired TV episodes, and interference attempts in the 2019 US elections, primarily targeting email accounts. Tools used by APT35 include DownPaper, which utilizes PowerShell and registry manipulation, Mimikatz for credential dumping, PsExec for remote execution, and PupyRAT for cross-platform control via phishing techniques.

    read more about Charming Kitten's Cyber Arsenal: Tools and Techniques Explained
  12. Public

    Sophisticated PowerShell Attack Targets Systems with Spearphishing

    The Fully Undetectable (FUD) PowerShell backdoor report details a sophisticated attack beginning with a malicious Word document ("Apply Form.docm") used in a LinkedIn-based spearphishing campaign originating from Jordan. The document contains a macro that launches a PowerShell script, creating a scheduled task to execute further malicious actions. The backdoor communicates with its C2 server, executing various commands such as process list exfiltration, user enumeration, and Active Directory exploration. SafeBreach identified operational security mistakes allowing decryption of the C2 commands. The campaign, involving PowerShell scripts and scheduled tasks, targets systems for data exfiltration and potential lateral movement.

    read more about Sophisticated PowerShell Attack Targets Systems with Spearphishing
  13. Public

    POLONIUM Cyber Espionage: Focused Attacks on Israeli Organizations Across Multiple Sectors

    The POLONIUM group has been actively targeting more than a dozen organizations in Israel since September 2021, with a focus on various sectors including engineering, IT, law, communications, branding and marketing, media, insurance, and social services. The group's arsenal comprises several custom backdoors like CreepyDrive, CreepySnail, DeepCreep, MegaCreep, FlipCreep, TechnoCreep, and PapaCreep, along with other spying modules. These backdoors utilize cloud services like OneDrive, Dropbox, and Mega for command and control operations and are involved in collecting confidential data without engaging in sabotage or ransomware activities. The initial access to targeted systems might have been gained through the abuse of leaked VPN credentials.

    read more about POLONIUM Cyber Espionage: Focused Attacks on Israeli Organizations Across Multiple Sectors
  14. Public

    Iranian Cyberattacks Disrupt Albanian Government Systems and Border Operations

    Iranian state-sponsored actors launched a series of cyberattacks against Albania, a NATO ally, targeting government systems. The initial attack on July 15, 2022, likely stemmed from Albania’s harboring of the Mujahedeen-e-Khalq (MEK) group. Subsequent attacks disrupted Albania’s Total Information Management System (TIMS), causing delays at borders and ports. Microsoft attributed the attack to Iranian-affiliated APTs, including EUROPIUM (APT34), using tools like ZeroCleare and Jason.exe for ransomware, data exfiltration, and disk wiping. The attacks leveraged vulnerabilities in public-facing applications and brute-force techniques. Albania severed diplomatic ties with Iran as a response, while the US condemned the attacks as a threat to NATO.

    read more about Iranian Cyberattacks Disrupt Albanian Government Systems and Border Operations
  15. Public

    Unveiling the Actors behind COBALT MIRAGE: A Ransomware Incident Analysis

    The Secureworks Counter Threat Unit analyzed a ransomware incident involving the Iranian COBALT MIRAGE threat group. The group exploited ProxyShell vulnerabilities, used a customized variant of Fast Reverse Proxy (FRPC) named TunnelFish, and encrypted servers using BitLocker. Despite attempts to erase their digital footprint, several tools and artifacts were recoverable, leading to the identification of associated individuals and entities, including Ahmad Khatibi, CEO of Afkar System Co., and Mansour Ahmadi, CEO of Najee Technology.

    read more about Unveiling the Actors behind COBALT MIRAGE: A Ransomware Incident Analysis
  16. Public

    Iranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns

    Iranian Islamic Revolutionary Guard Corps-affiliated cyber actors exploited vulnerabilities in Fortinet FortiOS, Microsoft Exchange, and VMware Horizon applications since early 2021, targeting entities in the U.S., U.K., and Australia. These vulnerabilities, including CVE-2018-13379, CVE-2020-12812, CVE-2019-5591, and several ProxyShell issues, were used for initial access, ransom operations, and data exfiltration. Activities include encrypting data for ransom, extortion operations, and crypto-mining, impacting sectors like law enforcement, transportation, municipal government, and aerospace. The actors leveraged tools like FRP, Plink, RDP, and BitLocker for command and control, lateral movement, and encryption.

    read more about Iranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns
  17. Public

    "Korg" in Action: How TA453 Leveraged Multi-Persona Impersonation in Spear Phishing

    The Iran-aligned threat actor TA453 has introduced a novel technique known as Multi-Persona Impersonation (MPI) to its spear-phishing campaigns. This method involves the simultaneous use of multiple false identities to enhance the credibility of their social engineering attacks. Alongside MPI, TA453 uses a malicious Word document exploiting Remote Template Injection, codenamed "Korg," to exfiltrate data.

    read more about "Korg" in Action: How TA453 Leveraged Multi-Persona Impersonation in Spear Phishing
  18. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  19. Public

    DEV-0270's Cyber Offensive: A Profiling of Their Ransomware Operations

    The DEV-0270 group, believed to be linked to the Iranian organization Secnerd/Lifeweb, has been conducting ransomware operations primarily by exploiting known vulnerabilities in Exchange and Fortinet. The group typically targets organizations with exposed and vulnerable servers. Their tactics involve account discovery, credential dumping, account creation, process injection, privilege escalation, and data encryption. They also use evasion techniques like disabling antivirus tools, and masquerading malicious activities under legitimate processes. Notably, the group uses lateral movement methods like Remote Desktop Protocol and WMIExec for propagation across networks.

    read more about DEV-0270's Cyber Offensive: A Profiling of Their Ransomware Operations
  20. Public

    CodeRAT Targets Farsi-Speaking Developers with Innovative C2 Techniques

    SafeBreach Labs has discovered CodeRAT, a new remote access trojan (RAT) targeting Farsi-speaking software developers with capabilities ranging from espionage to data exfiltration. Delivered via a Word document that exploits Microsoft DDE, CodeRAT monitors activity in various applications, particularly those related to social networking and development tools. Uniquely, it uses public file upload APIs and Telegram groups for command and control, bypassing typical C2 infrastructure. The malware supports 50 commands, including clipboard capture, process control and file upload. The CodeRAT developer released the source code on GitHub after it was discovered by researchers.

    read more about CodeRAT Targets Farsi-Speaking Developers with Innovative C2 Techniques
  21. Public

    MERCURY Turns to SysAid Applications for Targeted Cyberattacks in Israel

    The Iran-based threat actor MERCURY, linked to Iran's Ministry of Intelligence and Security (MOIS), was detected exploiting Log4j 2 vulnerabilities in SysAid applications against organizations in Israel. Using these exploits for initial access, MERCURY established persistence, dumped credentials, and moved laterally within the targeted organizations. The actor also utilized both custom and well-known hacking tools alongside built-in operating system tools. Microsoft has implemented detections against MERCURY's tools in its Defender Antivirus and Defender for Endpoint and has directly notified customers targeted or compromised by MERCURY.

    read more about MERCURY Turns to SysAid Applications for Targeted Cyberattacks in Israel
  22. Public

    Charming Kitten's HYPERSCRAPE Tool Found Stealing User Data from Email Accounts

    A new tool called HYPERSCRAPE, discovered by Google Threat Analysis Group in December 2021, has been found to be used by Charming Kitten to steal user data from Gmail, Yahoo and Microsoft Outlook accounts. HYPERSCRAPE requires the victim's account credentials to run, and once logged in, it changes the account's language settings to English, downloads messages individually as .eml files, and reverts the language back to its original settings once the inbox has been downloaded.

    read more about Charming Kitten's HYPERSCRAPE Tool Found Stealing User Data from Email Accounts
  23. Public

    UNC3890: The Iranian Nexus Behind Attacks on Israeli Shipping and Healthcare

    Mandiant's August 2022 report introduces UNC3890, a suspected Iranian-nexus threat actor tracked since late 2020, targeting Israeli shipping, government, energy, aviation, and healthcare organizations. Attribution indicators include Farsi language artifacts in malware code ("KHODA" meaning god, "yaal" meaning horse's mane), focused targeting of Israeli entities consistent with other Iranian actors, and a shared PDB path with UNC2448 (an IRGC-linked group). UNC3890 employs two custom tools: SUGARUSH — a small TCP reverse-shell backdoor that creates a "Service1" Windows service, connects to a hardcoded C2 on port 4585, and executes received CMD commands — and SUGARDUMP, a Chromium browser credential harvester with three observed versions: an early version (stores credentials locally), an SMTP version (exfiltrates via Yahoo/Yandex/Gmail using john.macperson2021 accounts, uses a robotic dolls commercial as lure), and an HTTP version (AES-CBC encrypted exfiltration to C2, uses a fake LexisNexis job offer lure). Initial access vectors include a watering hole on a legitimate Israeli shipping company's login page (sending victim data to xn--lirkedin-vkb[.]com), credential harvesting via lookalike domains (pfizerpoll[.]com, office365update[.]live, rnfacebook[.]com), spearphishing links, and potentially trusted relationships. Public tools used include Metasploit, UNICORN (Magic Unicorn), and NorthStar C2. IOCs include 8 C2 IPs, 10 domains (including a Punycode LinkedIn lookalike), 4 attacker email addresses, and 23 file hashes.

    read more about UNC3890: The Iranian Nexus Behind Attacks on Israeli Shipping and Healthcare
  24. Public

    Saitama Malware Uses DNS for Stealthy C2 Communications

    The Saitama implant, uncovered by Malwarebytes, uses DNS for Command and Control (C2) communications. Targeting the Jordan government, this malware employs domain randomization and long sleep times to evade detection. It encodes data using a shared key and a pseudo-random number generator, making detection challenging. The implant’s hardcoded sleep values and unique DNS queries ensure stealth, though the data transfer rate is slow.

    read more about Saitama Malware Uses DNS for Stealthy C2 Communications