Threats Feed
- Public
MuddyWater: Iranian APT Group Targets Global Networks Across Multiple Sectors
The Iranian government-sponsored APT group, MuddyWater, has been conducting cyber operations against government and private sector organizations across Asia, Africa, Europe, and North America. The targeted sectors include telecommunications, defense, local government, oil and natural gas. MuddyWater's campaigns involve the exploitation of public vulnerabilities, usage of open-source tools, spear-phishing, and the deployment of multiple types of malware such as PowGoop, Small Sieve, Canopy/Starwhale, Mori, and POWERSTATS. The group has been active since 2018 and is known for maintaining persistence on victim networks and obfuscating PowerShell scripts to hide C2 functions.
read more about MuddyWater: Iranian APT Group Targets Global Networks Across Multiple Sectors - Public
TunnelVision Exploits 1-Day Vulnerabilities to Unleash Ransomware
SentinelLabs tracks TunnelVision, an Iranian-aligned threat actor operating in the Middle East and the United States, characterized by wide exploitation of 1-day vulnerabilities and heavy reliance on tunneling tools. In early 2022, the group actively exploited the Log4Shell vulnerability (CVE-2021-44228) in VMware Horizon servers, spawning malicious processes via the Tomcat service to run PowerShell commands, deploy backdoors, create backdoor administrator accounts, harvest credentials via Procdump, SAM hive dumps, and comsvcs MiniDump, and perform lateral movement using Plink and Ngrok to tunnel RDP traffic. The group also previously exploited Fortinet FortiOS (CVE-2018-13379) and Microsoft Exchange ProxyShell (CVE-2021-34473). TunnelVision used a GitHub account ("protections20") to host payloads, and leveraged legitimate services including transfer.sh, pastebin.com, webhook.site, and ufile.io for C2 communication. A custom backdoor dropped as InteropServices.exe bears similarities to the PowerLess backdoor used by Phosphorus (Microsoft attribution), and the group has been linked to ransomware deployment — making it a potentially destructive actor beyond its espionage activities. SentinelLabs tracks this cluster separately from Phosphorus/Charming Kitten/Nemesis Kitten due to insufficient overlap data for a definitive merge.
read more about TunnelVision Exploits 1-Day Vulnerabilities to Unleash Ransomware - Public
Israeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group
The Moses Staff group has been orchestrating cyber attacks on various Israeli organizations since late 2020, using sophisticated tools and methodologies. Their primary mode of intrusion involved leveraging the ProxyShell exploit in Microsoft Exchange servers. Once in, they deployed two web shells and a complex backdoor mechanism, largely aimed at data exfiltration. Despite focusing primarily on espionage, the group's capabilities hint at potential for destructive attacks. The use of a hardcoded ID in the backdoor binary indicates that attacks may be personalized per target.
read more about Israeli Organizations Under Siege: Unpacking the Cyber Attacks by Moses Staff Group - Public
PowerLess Backdoor: Analyzing the Phosphorus Group's Cyber Espionage Tool
Iranian APT group Phosphorus has developed a new PowerShell backdoor, dubbed PowerLess Backdoor, for espionage purposes. Cybereason researchers discovered the backdoor while investigating the group's exploitation of the ProxyShell vulnerability. The backdoor allows for downloading additional payloads, evasive PowerShell execution, and encrypted communication with the command and control server. Connections were also found between the Phosphorus group and the Memento Ransomware.
read more about PowerLess Backdoor: Analyzing the Phosphorus Group's Cyber Espionage Tool - Public
StrifeWater: Unmasking the New RAT Deployed by Iranian APT Moses Staff
The Iranian APT group Moses Staff deployed a new, previously undocumented Remote Access Trojan (RAT) called StrifeWater for its cyber-espionage and disruption operations. The StrifeWater RAT has been used in initial attack stages, demonstrating various capabilities like listing system files, executing system commands, creating persistence, and downloading updates. Post-infection, it's replaced with ransomware not for financial gain but to disrupt operations and inflict system damage. Victims of these attacks span globally across countries like Israel, Italy, India, Germany, Chile, Turkey, UAE, and the US.
read more about StrifeWater: Unmasking the New RAT Deployed by Iranian APT Moses Staff - Public
Evolving Threat: MuddyWater APT's Multi-National Cyber Espionage Activities
The MuddyWater cyber-espionage group has been actively targeting Turkey, Armenia, and Pakistan in a sophisticated cyber campaign. Utilizing spearphishing techniques, they distributed malicious PDFs and Microsoft Office documents, often masquerading as official communications from Turkish ministries. These documents contained obfuscated PowerShell and Visual Basic scripts to establish persistence and download additional payloads. The campaign's tactics included living-off-the-land binaries, registry modifications for persistence, and the use of canary tokens for monitoring successful infections.
read more about Evolving Threat: MuddyWater APT's Multi-National Cyber Espionage Activities - Public
MuddyWater's Cyber Arsenal: From PowGoop to Mori Backdoor
US Cyber Command's Cyber National Mission Force (CNMF) published this advisory on January 12, 2022, disclosing multiple open-source tools used by MuddyWater — a subordinate element of Iran's Ministry of Intelligence and Security (MOIS) — in networks around the world. The advisory identifies several variants of the PowGoop malware suite and the Mori backdoor, and releases file samples to VirusTotal for defender use. PowGoop operates via DLL side-loading: the malicious goopdate.dll is placed alongside the legitimate GoogleUpdate.exe, causing it to load automatically. Once loaded, it deobfuscates a .dat PowerShell script, which in turn decodes a config.txt PowerShell script that establishes C2 communication using a modified Base64 encoding scheme. Additional PowGoop variants use different DLL names (libpcre2-8-0.dll, vcruntime140.dll) to avoid AV and manual detection. JavaScript samples associated with the same actor issue GET requests to malicious infrastructure. The Mori backdoor communicates with C2 infrastructure via DNS tunneling and is identified by two key indicators: creation of the mutex 0x50504060 and the registry key HKLM\SOFTWARE\NFC. CNMF noted that identifying multiple of these tools on the same network strongly indicates the presence of Iranian malicious cyber actors.
read more about MuddyWater's Cyber Arsenal: From PowGoop to Mori Backdoor - Public
Evolution of MuddyWater: Targeting Governmental and Telecom Sectors in the Middle East
The MuddyWater threat group continues to evolve its tactics and techniques. The group exploits publicly available offensive security tools and has been refining its custom toolset to avoid detection. It utilizes the PowGoop malware family, tunneling tools, and targets Exchange servers in high-profile organizations, particularly governmental entities and telecommunication companies in the Middle East. The group has also been observed exploiting CVE-2020-0688 and using Ruler for its malicious activities.
read more about Evolution of MuddyWater: Targeting Governmental and Telecom Sectors in the Middle East - Public
CharmPower: APT35's Modular Toolset Exploits Log4j Vulnerability
APT35 has started widespread scanning and attempts to leverage the Log4j flaw in publicly facing systems only four days after the vulnerability was disclosed. The group used a modular PowerShell-based framework dubbed CharmPower for persistence, information gathering, and command execution.
read more about CharmPower: APT35's Modular Toolset Exploits Log4j Vulnerability - Public
Seedworm Group Suspected in Sweeping Espionage Campaign Across Telecom and IT Services
An espionage campaign tentatively linked to the Iranian-backed Seedworm group has been using compromised organizations as stepping stones to additional victims or targets that may have been compromised solely to perform supply-chain-type attacks on other organizations. The attackers primarily used legitimate tools, publicly available malware, and living-off-the-land tactics, with a significant interest in Exchange Servers. While the ultimate end goal remains unknown, the focus on telecom operators suggests the attackers are gathering intelligence on the sector, potentially pivoting into communications surveillance.
read more about Seedworm Group Suspected in Sweeping Espionage Campaign Across Telecom and IT Services - Public
Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers
SafeBreach Labs discovered an Iranian threat actor exploiting the MSHTML vulnerability (CVE-2021-40444) to infect Farsi-speaking victims with the PowerShortShell stealer via spear phishing. The attack, first reported in September 2021, involved a malicious Word document connecting to a server, downloading a DLL, and executing a PowerShell script. This script collected data, including screenshots and files, and exfiltrated it to the attacker's server. The campaign targeted Iranians abroad, particularly in the United States, suggesting ties to Iran's Islamic regime.
read more about Iranian Threat Actor Exploits MSHTML Vulnerability to Target Farsi Speakers - Public
Iranian APT Group Exploits Microsoft and Fortinet Vulnerabilities: A Broad Spectrum Cyber Assault
Some Iranian government-sponsored APT groups have exploited vulnerabilities in Microsoft Exchange servers and Fortinet devices since March 2021. These actors broadly targeted critical infrastructure sectors in the US, including Transportation and Healthcare and Public Health, as well as Australian organizations. The APT group focused more on exploiting known vulnerabilities rather than specific sectors, using the gained access for ransomware deployment, data exfiltration, and extortion. Several tactics, techniques, and tools were utilized, including creating new user accounts and modifying Task Scheduler.
read more about Iranian APT Group Exploits Microsoft and Fortinet Vulnerabilities: A Broad Spectrum Cyber Assault - Public
Memento Team's Innovative Ransomware Strategy: Bypassing Encryption Detection
Sophos discovered a novel ransomware approach by "Memento Team," which bypasses encryption detection by copying files into password-protected archives. Initially attempting direct encryption thwarted by endpoint protection, the actors retooled their method. They demanded $1 million for file restoration, threatening data exposure. The attack exploited a VMware vCenter Server vulnerability, with the attackers gaining initial access through a misconfigured firewall. Their activities included lateral movement using stolen credentials and deployment of a Python-based keylogger. The attack leveraged various tools like WinRAR, Mimikatz, and PowerShell, culminating in file archiving for ransom. The targeted sectors or countries were not specified in the report.
read more about Memento Team's Innovative Ransomware Strategy: Bypassing Encryption Detection - Public
Political Motivation and Damage: Understanding the MosesStaff Cyberattacks
Check Point Research documents MosesStaff, an Iranian-linked group that began targeting Israeli organizations in September 2021 with explicitly destructive intent. Unlike financially motivated ransomware groups, the actors openly stated their goal was to damage Israeli companies by leaking stolen data and permanently encrypting their networks — with no ransom demand and no decryption option offered. Initial access was gained by exploiting known vulnerabilities in internet-facing infrastructure, particularly Microsoft Exchange servers, where a password-protected web shell was deployed. Lateral movement relied on PsExec, PowerShell, and WMIC using harvested administrator credentials. The group deployed two custom tools: PyDCrypt, a Python-compiled dropper tailored per victim with hardcoded network credentials, and DCSrv, a destructive encryptor built around the open-source DiskCryptor library. DCSrv encrypted all drive volumes using AES and installed a custom bootloader that prevented systems from starting without the correct password. The encryption key was derived from a per-hostname MD5 hash function — a design flaw that Check Point notes may allow decryption under certain conditions. Attribution artifacts, including a tool submission from Palestine and image metadata tied to GMT+3, suggest a Palestinian or Israeli-adjacent operator.
read more about Political Motivation and Damage: Understanding the MosesStaff Cyberattacks - Public
Iranian-backed PHOSPHORUS Exploits Microsoft Exchange Vulnerabilities for Data Encryption
The DFIR Report's November 2021 case study documents a PHOSPHORUS (APT35/Charming Kitten) intrusion in late September 2021 in which the attacker exploited the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) on an internet-facing Microsoft Exchange server. Over 42 hours, three web shells were deployed in OWA directories. The attacker used PowerShell and cmd.exe via web shells to run Exchange discovery cmdlets (Get-Mailbox, Get-ExchangeServer), then enabled the built-in DefaultAccount, set its password to P@ssw0rd, and added it to Administrators and Remote Desktop Users groups. Plink was used to establish an SSH tunnel to 148.251.71[.]182 (tcp.symantecserver.co), exposing RDP externally. LSASS was dumped via Task Manager. Fast Reverse Proxy (FRP, renamed to dllhost.exe) was deployed for persistent RDP proxying via a scheduled task named CacheTask. Using stolen domain admin credentials, the actors performed internal port scanning with KPortScan 3.0, moved laterally to backup systems and domain controllers via RDP, and deployed Impacket's wmiexec on one domain controller. The final impact was domain-wide encryption: BitLocker on servers (via setup.bat) and DiskCryptor on workstations via dcrypt.exe, with a ransom note requesting 8,000 USD left on an unencrypted domain controller. No data exfiltration or Cobalt Strike was used — notably rare for a ransomware intrusion of this scale.
read more about Iranian-backed PHOSPHORUS Exploits Microsoft Exchange Vulnerabilities for Data Encryption - Public
Lyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa
Prevailion and Accenture's November 2021 joint report documents Lyceum (also known as HEXANE or Spirlin) targeting telecommunications providers and ISPs in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a Ministry of Foreign Affairs in an unnamed African country. The campaign ran from at least July 2021 through November 2021. Lyceum deployed two updated malware families: Shark, a C#/.NET backdoor using HTTPS for C2 communication, and Milan, a Visual C++/.NET backdoor using DNS tunneling. Both support command execution, file upload and download, and system reconnaissance. Persistence is achieved via Windows scheduled tasks. XOR encoding is used to obfuscate C2 traffic. The group registered 26 C2 domains with security and Windows-update-themed naming patterns (e.g. defenderlive.com, dnsstatus.org, wsuslink.com, windowsupdatecdn.com). Two file hashes for Shark samples are documented. IOC overlap with earlier Lyceum campaigns confirms continuity of tooling and infrastructure across the group's operations from 2019 to 2021.
read more about Lyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa - Public
APT35 Cyber Espionage: From Phishing to Spyware and Beyond
APT35 has used multiple tactics to compromise high-value targets. The group has used hijacked websites, such as one affiliated with a UK university, for credential phishing attacks. They have also uploaded spyware disguised as VPN software to app stores and impersonated conference officials to conduct phishing campaigns. Additionally, APT35 has utilized link shorteners and click trackers embedded within PDF files and abused services like Google Drive, App Scripts, and Sites pages. The group has adopted a novel approach by leveraging Telegram for real-time operator notifications, enabling them to monitor visitor information to their phishing sites.
read more about APT35 Cyber Espionage: From Phishing to Spyware and Beyond - Public
Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware
Since 2007, the Infy Iranian threat group has been continuously active, launching sophisticated cyberattacks using Foudre and Tonnerre malware. Foudre collects data from infected machines and sends it to the C2 server, while Tonnerre, deployed if the victim is of interest, includes advanced spying capabilities like reverse shell and voice recording. Both use a domain generating algorithm (DGA) to evade detection by frequently changing domains. SafeBreach Labs developed a method to break Foudre’s DGA, allowing prediction and pre-emptive blocking of future C2 domains. This strategy neutralizes Foudre by preventing updates and new DGA acquisitions. The latest findings include the discovery of Tonnerre version 15 and Foudre version 24, indicating the group's evolving tactics. The report also uncovers changes in the Iranian group's infection strategy, targeting victims with both Foudre and Tonnerre, except those with certain security controls.
read more about Infy Group's Evolving Cyber Tactics: Unveiling Foudre and Tonnerre Malware - Public
Lyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors
The Lyceum group (also known as Hexane) is a cyber threat actor focused on the telecommunications, energy and aviation sectors, particularly targeting high-profile organisations in Tunisia. Active since 2018, Lyceum has recently replaced its .NET-based malware with new C++ backdoors and PowerShell scripts to evade detection. The group continues to rely on DNS tunneling for command and control (C2) and uses tools for system reconnaissance, credential theft and keylogging. Lyceum also uses spoofed domains to disguise its activities, demonstrating an adaptive approach to persistent targeting of critical infrastructure.
read more about Lyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors - Public
MalKamak Targets Middle Eastern Aerospace and Telecom Firms with ShellClient RAT
The Iranian APT group MalKamak has been targeting aerospace and telecommunications companies in the Middle East since at least 2018, with additional victims in the US, Russia and Europe. The group uses ShellClient, a newly discovered remote access trojan (RAT), to conduct highly targeted cyberattacks. ShellClient uses Dropbox, a popular cloud-based service, for command and control (C2) operations, replacing the group's previous C2 infrastructure.
read more about MalKamak Targets Middle Eastern Aerospace and Telecom Firms with ShellClient RAT - Public
MalKamak's GhostShell Campaign Hits Middle East, U.S., and Europe
Operation GhostShell is a cyber espionage campaign targeting aerospace and telecommunications companies, primarily in the Middle East, with victims in the U.S., Russia and Europe. The operation, carried out by the Iranian group MalKamak, uses a stealthy, evolving remote access trojan (RAT) called ShellClient, which has been in development since 2018. ShellClient evades detection through masquerading, AES encryption and WMI-based reconnaissance. The attackers used tools such as PAExec for lateral movement and lsa.exe for credential dumping. Data exfiltration was facilitated by using WinRar to compress stolen information before sending it via Dropbox.
read more about MalKamak's GhostShell Campaign Hits Middle East, U.S., and Europe - Public
Jennlog and Apostle: Unpacking Agrius's Ransomware Attack on Israeli Academia
Apostle ransomware was resurrected in a targeted attack by Agrius against Bar-Ilan University in Israel. The report details the use of a custom loader, Jennlog, to obfuscate, encrypt, and compress the ransomware. Jennlog disguises the payload within seemingly innocuous log files and conducts environment checks to evade detection. This version of Apostle, compiled on the day of the attack, encrypts victim data, demanding a ransom and altering desktop wallpapers to display a clown image. Additionally, another Jennlog variant was found loading OrcusRAT, indicating broader malicious capabilities of the threat actor.
read more about Jennlog and Apostle: Unpacking Agrius's Ransomware Attack on Israeli Academia - Public
Siamesekitten APT Targets Israeli IT Firms with Supply Chain Attacks
The Iranian APT group Siamesekitten (Lyceum/Hexane) launched targeted cyberattacks on Israeli IT and technology firms in 2021 using advanced social engineering and supply chain tactics. The campaign impersonated HR personnel and organizations via phishing websites and LinkedIn profiles to distribute malware such as Milan and its successor Shark. Victims were infected with DanBot RAT through DNS tunneling and HTTPS C2 communication. The group also exploited legitimate tools like UltraVNC for remote access. Known for prior attacks on oil, gas, and telecom sectors in the Middle East and Africa, Siamesekitten’s recent focus highlights its shift to Israeli targets for espionage and data theft.
read more about Siamesekitten APT Targets Israeli IT Firms with Supply Chain Attacks - Public
TA456's Advanced Espionage Tactics Against Defense Contractors Using LEMPO Malware
The report from Proofpoint outlines a complex social engineering and malware campaign that appears to have been conducted by an actor aligned with the Iranian state, believed to be TA456. Over several years, TA456 used a fake social media persona, "Marcella Flores," to build a relationship with an employee of an aerospace defense contractor. The aim was to infect the target's computer with the LEMPO malware, designed for reconnaissance and data exfiltration. This campaign serves to illustrate TA456's persistence and advanced social engineering tactics, targeting smaller contractors with the ultimate goal of eventually compromising larger defense firms.
read more about TA456's Advanced Espionage Tactics Against Defense Contractors Using LEMPO Malware