Chafer APT Targets Iranian Diplomatic Entities with Updated Remexi Malware
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Keylogger,Spyware,Trojan
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
Throughout autumn 2018, Kaspersky researchers identified an active cyber-espionage campaign attributed to the Iran-based Chafer group, targeting foreign diplomatic entities operating inside Iran. The attackers deployed an updated version of Backdoor.Remexi — a Windows trojan capable of logging keystrokes, capturing screenshots, stealing browser credentials and history, and executing remote commands. The malware relied heavily on Microsoft's Background Intelligent Transfer Service (BITS) for both receiving commands and exfiltrating collected data, blending malicious traffic with legitimate Windows activity. Persistence was maintained through scheduled tasks and registry modifications. Encryption used XOR and RC4 algorithms with unique per-sample keys; one sample used the Farsi word for "health" as a key, reinforcing Iranian attribution. Kaspersky assessed the campaign as a likely domestic counter-intelligence operation.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services Foreign diplomatic entities based in Iran were targeted in the attack. | Verified |
| Region | Iran The country targeted by the attack is Iran. | Verified |
Extracted IOCs
- 028515d12e9d59d272a2538045d1f636
- 03055149340b7a1fd218006c98b30482
- 12477223678e4a41020e66faebd3dd95
- 1ff40e79d673461cd33bd8b68f8bb5b8
- 25469ddaeff0dd3edb0f39bbe1dcdc46
- 41b2339950d50cf678c0e5b34e68f537
- 460211f1c19f8b213ffaafcdda2a7295
- 4bf178f778255b6e72a317c2eb8f4103
- 53e035273164f24c200262d61fa374ca
- 7d1efce9c06a310627f47e7d70543aaf
- 9f313e8ef91ac899a27575bc5af64051
- aa6246dc04e9089e366cc57a447fc3a4
- c6721344af76403e9a7d816502dca1c8
- c981273c32b581de824e1fd66a19a281
- d3a2b41b1cd953d254c0fc88071e5027
- dcb0ea3a540205ad11f32b67030c1e5a
- ecae141bb068131108c1cd826c82d88b
- a77f9e441415dbc8a20ad66d4d00ae606faab370ffaee5604e93ed484983d3ff
- b1fa803c19aa9f193b67232c9893ea57574a2055791b3de9f836411ce000ce31
- 108[.]61.189.174
Tip: 20 related IOCs (1 IP, 0 domain, 0 URL, 0 email, 19 file hash) to this threat have been found.
FAQs
Frequently Asked Questions: Chafer's Remexi Campaign Against Foreign Diplomats in Iran
Throughout autumn 2018, the Iran-linked Chafer APT group ran a targeted cyber-espionage campaign against foreign diplomatic missions based in Iran. The attackers used an updated and more capable version of the Remexi malware to silently collect sensitive information from victim computers — including keystrokes, screenshots, browser data, and credentials — and send it back to attacker-controlled servers. Kaspersky researchers, who analyzed the campaign while it was still active, described it as a likely domestic counter-intelligence operation.
The attack was carried out by Chafer, also tracked as APT39, an Iran-based threat group previously documented by Symantec. Kaspersky attributed the campaign based on the use of Remexi malware — a tool historically associated with Chafer — and additional cultural indicators within the malware code. Notably, one sample used the Farsi word "salamati" (meaning "health") as an encryption key, strongly suggesting Iranian operators. The targeting of foreign diplomats inside Iran points to a state-directed surveillance effort.
This was a cyber-espionage operation aimed at collecting intelligence from foreign diplomatic personnel operating inside Iran. The malware was designed to comprehensively monitor victims — capturing keystrokes, taking screenshots of specific windows, stealing browser credentials and browsing history, and recording clipboard activity. The attackers could also execute remote commands on victim machines. The goal was persistent, covert surveillance rather than disruption or financial gain.
The campaign was geographically narrow but strategically significant — focused entirely on foreign diplomatic entities based inside Iran. Kaspersky's telemetry confirmed the campaign was active for at least several months during autumn 2018 and was still ongoing at the time of analysis. Only Iran appears as a confirmed targeted country, but the victims were foreign nationals and missions from multiple countries stationed there, making the potential intelligence reach considerably wider.
The primary targets were foreign diplomatic missions and their staff based in Iran — embassies, consulates, and similar government entities. The attackers configured the malware to capture activity on specific windows of interest, including those related to VPN logins, email, and security tools, suggesting they were particularly interested in communications and credentials used by diplomatic personnel.
The malware was likely delivered via a compiled AutoIt dropper that used hardcoded FTP credentials to fetch and install Remexi on victim machines. Once installed, Remexi established persistence through Windows scheduled tasks and registry run keys, then began silently collecting data. It used Microsoft's Background Intelligent Transfer Service (BITS) — a legitimate Windows file transfer tool — to receive commands from attackers and upload stolen data, disguising malicious traffic as normal system activity. All collected data was encrypted before being sent to the attacker's server.
Foreign diplomatic missions hold sensitive government communications, classified cables, travel plans, and contacts with local sources — all of high intelligence value to a host state seeking to monitor foreign influence on its territory. By compromising diplomatic computers, the attackers could intercept communications before encryption, capture login credentials for secure systems, and track the activities of foreign officials. This type of access is difficult to obtain through other means and provides persistent, real-time intelligence.
Diplomatic missions and their staff should monitor endpoints for unusual use of Windows built-in tools — particularly `bitsadmin.exe` making outbound HTTP connections, unexpected scheduled tasks, and unauthorized modifications to Winlogon registry keys. Deploy and keep updated endpoint security solutions capable of detecting Trojan.Win32.Remexi. Restrict the use of `bitsadmin.exe` and `wmic.exe` where not operationally needed. Regularly audit browser credential stores and consider using hardware security keys to reduce the impact of credential theft. Assume that communications on compromised endpoints may have been intercepted and rotate credentials accordingly.