Latest Update27/08/2026

Threats Feed

  1. Public

    Cyber Espionage in Albania: Tracing the Links Between ROADSWEEP, CHIMNEYSWEEP, and Iranian Actors

    In July 2022, Mandiant uncovered the ROADSWEEP ransomware, targeting the Albanian government with a politically motivated campaign. The operation, claimed by “HomeLand Justice,” disrupted Albanian government websites and services. This group also shared videos and documents suggesting ties to the Iranian opposition group MEK. Concurrently, CHIMNEYSWEEP, a backdoor linked to ROADSWEEP, was identified, targeting Farsi and Arabic speakers, including the Iranian diaspora, with capabilities like keylogging and file collection. Both ROADSWEEP and CHIMNEYSWEEP shared code and encryption methods. Additionally, a ZEROCLEAR wiper payload was reported, potentially linked to Iranian threat actors, known for targeting Middle Eastern entities.

    read more about Cyber Espionage in Albania: Tracing the Links Between ROADSWEEP, CHIMNEYSWEEP, and Iranian Actors
  2. Public

    Yellow Garuda's New Arsenal: Telegram 'Grabber' Tool and Android Malware in Focus

    Yellow Garuda has been observed using a new Telegram 'grabber' tool alongside Android malware for domestic targeting, including victims likely linked to the Iranian music industry. The threat actor has been active since 2012, primarily using phishing attacks to harvest credentials. Despite operational security errors, Yellow Garuda has expanded its toolset to include macro-enabled template files. The observed document lures used themes related to nuclear energy, weapons, US shipping ports, and Iran's relationship with the Taliban, indicating potential targeting of a wide range of sectors.

    read more about Yellow Garuda's New Arsenal: Telegram 'Grabber' Tool and Android Malware in Focus
  3. Public

    Iranian APTs Exploit Media Sector for Credential Harvesting and Malware Delivery

    This Proofpoint report details the escalating targeting of journalists and media organisations by state-sponsored advanced persistent threats (APTs). The report highlights how groups linked to China (TA412, TA459), North Korea (TA404), Iran (TA453, TA456, TA457), and Turkey (TA482) are using a variety of methods, including phishing emails with malicious attachments or web beacons for reconnaissance and social media credential harvesting, to achieve their intelligence and propaganda goals. The report highlights the persistent nature of the threat, the variety of tactics used, and the importance of enhanced security measures for journalists to protect their sources and the integrity of their reporting. Ultimately, it aims to raise awareness of this specific cybersecurity threat and encourage proactive protection measures within the media sector.

    read more about Iranian APTs Exploit Media Sector for Credential Harvesting and Malware Delivery
  4. Public

    OilRig Campaigns: Phishing and PowerShell Attacks on Global Sectors

    AttackIQ has released attack graphs emulating OilRig’s operations against global sectors, based on reports from Mandiant, Intezer, and Palo Alto Networks. The 2020 social media phishing campaign used LinkedIn to distribute malicious documents, leading to the Tonedeaf backdoor installation, persistence via scheduled tasks, and credential dumping with tools like LaZagne. The 2018 QuadAgent campaign targeted technology service providers and government agencies with PowerShell malware, establishing persistence, and utilizing multi-channel command-and-control communication, including SSL, HTTP, and DNS.

    read more about OilRig Campaigns: Phishing and PowerShell Attacks on Global Sectors
  5. Public

    APT34’s Saitama Agent: Phishing and DNS Tunneling in Jordan

    APT34's Saitama Agent employs a spear phishing email with a malicious Excel attachment to deliver malware using unique DNS tunneling and stateful programming techniques. The Excel document contains a VBA macro that hides its activities and communicates with the C2 server using DNS requests. The macro checks for mouse connections, drops multiple files, and uses a scheduled task for persistence. The campaign appears to be targeting Jordan, leveraging a Jordanian government ministry's logo to deceive victims.

    read more about APT34’s Saitama Agent: Phishing and DNS Tunneling in Jordan
  6. Public

    Iranian Lyceum Group Deploys Malware Disguised as Adobe Update

    The Iranian SiameseKitten (Lyceum) group deployed new malware masquerading as an Adobe update, communicating with a command and control server. The malware includes a reverse shell and employs fake Microsoft certificates, echoing tactics seen with other Iranian groups like Phosphorus. The attack involved a lure PDF related to drone attacks in Iran, aiming to establish persistence via the Startup folder. The parent file and reverse shell were downloaded from domains registered on June 6th, highlighting the group's continued use of sophisticated detection avoidance techniques.

    read more about Iranian Lyceum Group Deploys Malware Disguised as Adobe Update
  7. Public

    MuddyWater's Malicious Macros: A Long-Term Threat to Middle Eastern Nations

    The MuddyWater threat group has been conducting a long-term infection campaign targeting Middle East countries since the last quarter of 2020. The campaign utilizes a malicious Word document containing VBA macros wrapped in a compressed file to compromise victims' systems. The VBA macros drop a concise VBS script, which functions as a small RAT, allowing the execution of commands via cmd and communication with a C2 server using HTTP GET and POST requests. The targeted countries include Pakistan, Kazakhstan, Armenia, Syria, Israel, Bahrain, Turkey, South Africa, Sudan, and others in the Middle East region.

    read more about MuddyWater's Malicious Macros: A Long-Term Threat to Middle Eastern Nations
  8. Public

    Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing

    In early January 2021, Proofpoint researchers identified the Iran-aligned APT actor TA451 (also known as APT33) running a spearphishing campaign against a US defense contractor using COVID-19-themed lures. The actor masqueraded as the World Health Organization, delivering emails with a link to a malicious executable named COVID19tracker[.]exe. Once a user executed the file, it reached out to download a batch script (iehchecker[.]bat), which in turn retrieved a PowerShell script (Update-KB4524147[.]ps1) with reverse shell capabilities, giving the attacker remote access to the compromised host. The campaign is documented as a case study in TA451's social engineering tradecraft within Proofpoint's broader 2022 Social Engineering Report, which covers threat actor tactics observed throughout 2021 — including multi-stage infection chains, impersonation of trusted organizations, and exploitation of topical events to lower victim defenses.

    read more about Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing
  9. Public

    Phosphorus Targets Israeli and US Officials with Spear-Phishing

    This report from Check Point Research details an Iranian spear-phishing campaign targeting high-profile former Israeli and US officials. According to Check Point, the high-profile targets of this operation include Tzipi Livni, former Israeli Foreign Minister and Deputy Prime Minister; a former major general in the Israeli Defence Forces (IDF) who held a highly sensitive position; the chairman of a leading Israeli security think tank; a former US ambassador to Israel; the former chairman of a prominent Middle East research centre; and a senior executive in the Israeli defence industry. The attackers used sophisticated techniques, including email thread hijacking and a custom URL shortener, to trick victims into revealing sensitive information. A legitimate identity verification service was also exploited to steal identity documents. The report analyses the attack infrastructure, methods and possible attribution to the Iran-linked Phosphorus APT group, suggesting a motive that may be linked to escalating geopolitical tensions between Iran and Israel. The ultimate goal appears to be access to victims' inboxes and personally identifiable information (PII), although the possibility of physical harm is also considered.

    read more about Phosphorus Targets Israeli and US Officials with Spear-Phishing
  10. Public

    Understanding Saitama: The Latest Weapon in APT34's Cyber Arsenal

    Renato Marinho of Morphus Labs (SANS ISC) provides a technical decoder analysis of Saitama's novel DNS tunneling C2 mechanism, complementing the Malwarebytes discovery reports. Saitama's key innovation is encoding attacker commands directly inside IPv4 address octets returned by the C2 nameserver — rather than using DNS TXT records or other large-payload record types. The first octet carries a control code (indicating whether a command or payload is being issued), and the subsequent three octets encode three ASCII characters of the command. For example, to issue 'whoami', the server returns two IPs: 70.119.104.111 (control byte 70; w=119, h=104, o=111) and 97.109.105.49 (control byte 97; a=109, m=105, i=49). This approach makes commands indistinguishable from ordinary A-record DNS responses in environments that do not inspect IPv4 address content. Data exfiltration flows in the opposite direction: the victim encodes command output in chunked subdomain strings of attacker-controlled domains (joexpediagroup[.]com, uber-asia[.]com), reassembled by the C2. Marinho captured a live 'ver' exfiltration session reconstructing "Microsoft Windows [Version 10.0.18363.418]" across four DNS queries. The Saitama binary is a .NET assembly that can be readily decompiled, and Morphus Labs released an open-source decoder tool (saitama_translator) on GitHub to help defenders translate captured DNS sessions from infected hosts. The author notes the accessibility of Saitama's implementation could encourage other threat actors to adopt similar IPv4-encoding DNS tunneling techniques.

    read more about Understanding Saitama: The Latest Weapon in APT34's Cyber Arsenal
  11. Public

    Lyceum Group Unveils Stealthy .NET DNS Backdoor in Middle East Campaign

    Zscaler ThreatLabz's June 2022 report documents a new Lyceum Group campaign deploying a .NET-based DNS backdoor named DnsSystem — a customized version of the open-source DIG.net tool — against targets in the Middle East. The malware was delivered via a macro-enabled Microsoft Word document disguised as a news report related to Iranian military affairs, with C2 infrastructure at news-spot.live (85.206.175.199). The document dropped and executed the DnsSystem backdoor, which uses DNS Hijacking for command-and-control: it communicates with the attacker by sending queries to a malicious DNS server and parsing TXT and A record responses for commands. Supported functions include remote command execution, file upload to and download from the C2 server, process and application window discovery, network configuration discovery, and security tool detection. Persistence is achieved by dropping the backdoor binary into the Windows Startup folder. C2 traffic is Base64-encoded. IOCs include 1 IP address (85.206.175.199), 2 domains (news-spot.live, cyberclub.one), 5 URLs, and 2 file hashes. IOC overlap with a concurrent Lyceum campaign (Check Point, March 2022) confirms the same actor and infrastructure.

    read more about Lyceum Group Unveils Stealthy .NET DNS Backdoor in Middle East Campaign
  12. Public

    Iranian-Linked POLONIUM Targets Israeli Manufacturing and Defense Industries

    POLONIUM, suspected to be coordinating with Iran's Ministry of Intelligence and Security, is actively targeting Israeli organizations across multiple sectors such as critical manufacturing, IT, and defense. The group exploits supply chain vulnerabilities by compromising IT companies to further target downstream organizations like aviation companies and law firms. TTPs include custom implants like CreepyDrive that use cloud services for C2 and data exfiltration. MSTIC also notes overlap with Iranian groups MERCURY, CopyKittens, both in targeted victims and techniques like using AirVPN and OneDrive. Though unconfirmed, around 80% of victims were observed running Fortinet appliances, suggesting a potential CVE-2018-13379 exploitation.

    read more about Iranian-Linked POLONIUM Targets Israeli Manufacturing and Defense Industries
  13. Public

    Stealth in the System: PHOSPHORUS Exploits Exchange Server in Infrastructure Sector Attack

    Deep Instinct researchers detected suspicious activity in a Southern U.S. infrastructure and construction company, revealing an attempted compromise of an Exchange server by an Iranian APT, PHOSPHORUS. Seven exploitation attempts were made, including installation of a root certificate and blending malicious traffic with legitimate. The attacker used malware to create a new user account, setup RDP access, and establish a reverse proxy to connect to the compromised system. A new evasion technique, involving masking malicious domains within legitimate ones, was also detected. PHOSPHORUS activities can be traced back to June 2020.

    read more about Stealth in the System: PHOSPHORUS Exploits Exchange Server in Infrastructure Sector Attack
  14. Public

    APT34 Uses Saitama Backdoor to Attack Jordanian Government through DNS Tunnelling

    Malwarebytes Threat Intelligence details the complete four-step DNS tunneling state machine used by the Saitama backdoor in APT34's attack on Jordan's Foreign Ministry. The maldoc was an Excel file named "Confirmation Receive Document.xls" — a spearphishing attachment that, when opened, installed Saitama (update.exe) and established persistence via Office template macros. All C2 communication runs over DNS using three interchangeable lookalike domains (uber-asia[.]com, asiaworldremit[.]com, joexpediagroup[.]com). Saitama's key evasion design addresses two DNS-specific problems: unencrypted traffic (solved with message obfuscation) and aggressive caching (solved by incrementing a counter with every request, which generates a unique custom base36 alphabet per message via substitution cipher, ensuring no two DNS queries look the same). The four-stage protocol works as follows: (1) Make Contact — Saitama picks a random counter (0–46655), encodes an initial beacon including the string "aharuto" using the counter-derived alphabet, and receives a unique agent ID in the last octet of the C2's A-record response; (2) Ask for Command — Saitama encodes its agent ID and signals readiness; the C2 responds with the payload size encoded in the final three octets of the IP address (first octet 129–255 acts as a signal byte); (3) Get Command — Saitama retrieves the encoded command, with the first IP octet identifying one of five functions (43=Static, 70=Cmd, 71=CompressedCmd, 95=File, 96=CompressedFile) and remaining octets carrying ASCII command bytes; (4) Run Command — output is chunked into 12-byte segments, individually encoded, and exfiltrated via further DNS queries. The C2 domain is chosen at random from the three root domains at each step, further varying the traffic profile.

    read more about APT34 Uses Saitama Backdoor to Attack Jordanian Government through DNS Tunnelling
  15. Public

    Unveiling APT34’s Advanced Attack Tactics: From Excel Macros to DNS Tunneling

    FortiGuard Labs provides the most detailed technical analysis of the Saitama campaign against a Jordanian diplomat, identifying unique techniques across both the Excel macro and the dropped backdoor. The spearphishing email posed as a colleague from the target's own IT department, using the real employee's first and last name — an insider-impersonation lure rather than a generic government spoofing attempt. The Excel macro uses a sheet visibility toggle as an anti-emulation technique (targeting tools like ViperMonkey that may not support all Excel features), and beacons nine distinct execution states to the C2 via WMI Win32_PingStatus queries with unique subdomain prefixes per step, allowing the attacker to monitor macro progress in real time through their DNS logs. Three payload files are decoded from base64 UserForm label captions: update.exe (malware), update.exe.config (configuration), and a signed Microsoft.Exchange.WebServices.dll (clean, for legitimacy). The scheduled task "MicrosoftUpdate" runs every 4 hours using deprecated IdleSettings (10-minute idle requirement) for up to 20 days. The Saitama backdoor uses a Mersenne Twister PRNG seeded with an agent ID to generate DGA subdomains across three lookalike C2 domains; it validates DNS A-record responses by requiring the first octet to be ≥ 128 before treating the response as valid C2 data. Exfiltration uses Base32 encoding (consistent with APT34's DNSpionage tool) compressed before encoding. A mutex (726a06ad-475b-4bc6-8466-f08960595f1e) prevents concurrent execution. The C2 IP 193.239.84.207 has historical associations with NSO Group Pegasus, APT34, and GoziIFSB infrastructure. Fortinet assesses the 6–8 hour sleep is deliberately timed for a diplomat's work schedule, and the hardcoded internal network commands suggest prior limited access to the target network before this spearphishing attempt was made.

    read more about Unveiling APT34’s Advanced Attack Tactics: From Excel Macros to DNS Tunneling
  16. Public

    ENT-11: Iranian APT Group's PowGoop Attacks Uncovered

    The Iranian APT group ENT-11, also known as MuddyWater, has been using a variant of the PowGoop malware, dubbed "E400", targeting foreign governments, telecommunications, energy sectors, intergovernmental economic cooperation organizations, and the banking sector, primarily in the Middle East. Insights from NTT Security revealed dozens of PowGoop command and control servers dating back to October 2020. The group appears to be winding down operations with the E400-PowGoop variant, but it is expected to continue modifying its tools and creating new variants.

    read more about ENT-11: Iranian APT Group's PowGoop Attacks Uncovered
  17. Public

    APT34 Targets Jordan's Government with Saitama Backdoor: A New Wave of Cyber Espionage

    Malwarebytes Threat Intelligence documents the discovery of Saitama, a new APT34 backdoor found in a spearphishing attack on April 26, 2022 against a government official at Jordan's Foreign Ministry. The malicious email was sent from a Microsoft Outlook account impersonating a Jordanian government official — using the Jordan coat of arms as a signature — with an Excel attachment named "Confirmation Receive Document.xls." The macro runs on WorkBook_Open(), uses a WMI Win32_PingStatus query (rather than standard DNS resolution) to beacon execution steps to the C2, implements a mouse-check anti-sandbox technique (only executing if a mouse is detected), creates a %APPDATA%/MicrosoftUpdate directory, writes three payload components (Update.exe, Update.exe.config, Microsoft.Exchange.WenServices.dll) decoded from Base64 UserForm labels, and establishes persistence via a scheduled task named "MicrosoftUpdate." The Saitama backdoor (PDB: E:\Saitama\Saitama.Agent\obj\Release\Saitama.Agent.pdb) is a .NET finite state machine with states: BEGIN, ALIVE (fetches C2 via PRNG-seeded Mersenne Twister subdomains), SLEEP/SECOND SLEEP (up to 6–8 hours on failed DNS), RECEIVE, DO, and SEND/SEND AND RECEIVE. Its 22 hardcoded predefined commands include network reconnaissance (whoami, net user, hostname, systeminfo, TCP connections, DNS server addresses) alongside internal IP ping sweeps and nslookup queries targeting internal Jordanian government FQDNs (ise-posture.mofagov.gover.local, webmail.gov.jo), confirming prior knowledge of the victim network. Attribution to APT34 rests on maldoc similarities with prior APT34 campaigns (including the same mouse anti-sandbox and ENotif beacon pattern), Jordan government targeting history, and DNS C2 with Base32/Base36 encoding consistent with DNSpionage and prior Mandiant-reported APT34 campaigns.

    read more about APT34 Targets Jordan's Government with Saitama Backdoor: A New Wave of Cyber Espionage
  18. Public

    The Shadow of Rocket Kitten: Exploring a Sophisticated VMware Exploit

    Morphisec identified exploitation of a VMware Workspace ONE Access vulnerability, believed to be the work of an APT group, likely the Iranian-linked Rocket Kitten. The attack involved server-side template injection and execution of PowerShell commands via the Tomcat prunsrv.exe process application, leading to full remote code execution. The attackers deployed a PowerShell stager that downloaded the PowerTrash Loader. The end payload was a Core Impact Agent. The tactics are known to enable ransomware or coin miners deployment, evading typical defenses like antivirus and endpoint detection and response.

    read more about The Shadow of Rocket Kitten: Exploring a Sophisticated VMware Exploit
  19. Public

    Lyceum's Multi-Dropper Cyber Attack Targets Israeli and Saudi Entities

    Check Point Research's March 2022 report documents a Lyceum APT campaign that exploited the Russia-Ukraine war as a lure to target Israeli energy companies and entities in Saudi Arabia. In mid-March 2022, an Israeli energy organization received a spearphishing email from inews-reporter@protonmail[.]com with the subject "Russian war crimes in Ukraine," containing a link to a malicious document on news-spot[.]live hosting a Guardian article as a decoy. The campaign deployed three categories of executable droppers — a .NET DNS dropper, a .NET TCP dropper, and a Golang dropper — each delivering a different backdoor. The .NET DNS backdoor is a modified version of the DnsDig tool using the Heijden.DNS open-source library for DNS tunneling, supporting file upload/download and command execution. The .NET TCP backdoor communicates over raw TCP sockets with a configurable protocol, supporting command execution, screenshots, file listing, installed applications enumeration, and file upload/download/execution. The Golang HTTP backdoor operates in three stages (connectivity check, victim registration, command retrieval) using HTTP POST requests to /GO/1.php, /GO/2.php, and /GO/3.php. All droppers display a decoy PDF (Russia-Ukraine war related or Iranian cyber threat report) while silently downloading and executing the payload. Persistence is achieved via Startup folder placement or scheduled tasks. Attribution indicators include use of Heijden.DNS, DNS tunneling C2, infrastructure overlap with known Lyceum servers on the same ASN, and Protonmail registration addresses.

    read more about Lyceum's Multi-Dropper Cyber Attack Targets Israeli and Saudi Entities
  20. Public

    MuddyWater's Strategic Cyber Campaigns Across Turkey, Armenia, and Pakistan

    The Iranian-linked conglomerate MuddyWater, utilizing subgroups focused on regional targets, has launched sophisticated cyberattacks against Turkey, Armenia, and Pakistan through various campaigns. Employing tactics such as spearphishing with malicious attachments, PowerShell-based downloaders, and maldoc-based infection vectors, these campaigns primarily leveraged obfuscated files and malicious macros to establish persistence, execute arbitrary commands, and gather system information. Notably, the attackers used a token-tracking system to monitor infection success rates and deployed the SloughRAT for command and control, alongside VBS and JS-based downloaders for further infiltration.

    read more about MuddyWater's Strategic Cyber Campaigns Across Turkey, Armenia, and Pakistan
  21. Public

    TunnelVision Threat Actor Exploits Log4Shell Vulnerability in VMware Horizon Servers

    In early February 2022, the TunnelVision threat actor exploited a vulnerable VMware Horizon server using the Log4Shell vulnerability (CVE-2021-44228) to gain unauthorized access. The attack involved suspicious account creation, credential harvesting, and lateral movement using PSexec and RDP. The adversaries also harvested credentials using Procdump and downloaded Sysinternals and SSH tools. The intrusion was attributed to the Iranian-aligned TunnelVision activity cluster, based on observed TTPs and artifacts. The targeted sectors and countries are not specified in the report.

    read more about TunnelVision Threat Actor Exploits Log4Shell Vulnerability in VMware Horizon Servers
  22. Public

    MuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

    The joint alert by the FBI, CISA, CNMF, and NCSC-UK highlights the Iranian APT group MuddyWater's cyber-espionage activities using new malware like PowGoop, Small Sieve, Canopy (Starwhale), Mori, and POWERSTATS. These tools facilitate malicious activities such as DLL side-loading, encrypted communication via Telegram, data exfiltration via DNS tunneling, and credential theft. PowGoop mimics legitimate Google Update processes, while Small Sieve establishes persistence through registry keys. Canopy targets victims through spearphishing with malicious Excel attachments, indicating a focus on espionage.

    read more about MuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics
  23. Public

    Analysis of MuddyWater Malware Targeting Diverse International Sectors

    The analysis by multiple cybersecurity agencies, including the FBI and NSA, reveals MuddyWater's extensive use of the POWGOOP malware family among other malicious tools in cyber espionage activities. Targeting sectors such as telecommunications, defense, local government, and oil and natural gas, MuddyWater has impacted organizations across Asia, Africa, Europe, and North America. The analyzed malware employed techniques like DLL side-loading, PowerShell scripts for command execution, and data exfiltration via encrypted channels to C2 servers. These actions are part of a broader Iranian government-sponsored initiative, indicating a significant threat to global security infrastructure.

    read more about Analysis of MuddyWater Malware Targeting Diverse International Sectors
  24. Public

    The Rise Of GRAMDOOR And STARWHALE In The Middle East: UNC3313 Suspected

    The Iranian cyber espionage group UNC3313, also known as TEMP.Zagros and MuddyWater, has been identified as the perpetrator of a series of cyber attacks on Middle Eastern government and technology entities. The group used new targeted malware, GRAMDOOR and STARWHALE, to exploit vulnerabilities and gain unauthorized access. UNC3313 also utilized publicly available remote access software and modified open-source offensive security tools for lateral movement within the targeted systems. The group's activities suggest a strong focus on geopolitical targets and the telecommunications sector in the Middle East. The use of the Telegram API for command and control allows for malicious traffic to blend in with legitimate user behavior, indicating the group's efforts to evade detection.

    read more about The Rise Of GRAMDOOR And STARWHALE In The Middle East: UNC3313 Suspected