Threats Feed|Mermaid|Last Updated 26/05/2026|AuthorCertfa Radar|Publish Date24/03/2020

Operation Mermaid: A Decade of Targeted APT Attacks on Government Entities

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Downloader,Keylogger,Malware,RAT,Trojan,Phishing,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Operation Mermaid, an APT campaign active since April 2010, targeted government entities, specifically the Denmark Embassy and the Ministry of Foreign Affairs of Denmark. This six-year operation utilized phishing emails and watering hole attacks to deliver malicious code, evidenced by 284 malicious samples and 35 C&C domains. Analysis revealed the primary aim was data theft from English and Persian speaking countries. The SD RAT malware, disguised as legitimate files, played a key role in these attacks, featuring keylogging and data exfiltration capabilities. Differences in malware versions and tactics, including a unique check for Avast antivirus, suggest evolving strategies to evade detection.

Detected Targets

TypeDescriptionConfidence
CaseMinistry of Foreign Affairs of Denmark
The Ministry of Foreign Affairs of Denmark and its overseas representations are in charge of the Danish Realm's foreign policy and relations. Among these tasks are policy towards the Arctic Council, European Union, Nordic Council, development aid, trade policy and legal affairs in relation to the outside world. Ministry of Foreign Affairs of Denmark has been targeted by Mermaid as the main target.
Verified
RegionDenmark
Verified

Extracted IOCs

  • bestupdateserver[.]com
  • bestwebstat[.]com
  • myblog2000[.]com
  • short-name[.]com
  • updateserver1[.]com
  • aj58mail-box@yahoo[.]com
  • am54ja@yahoo[.]com
  • aminjalali_58@yahoo[.]com
  • kamil_r@mail[.]com
  • 0096c70453cd7110453b6609a950ce18
  • 1a918a850892c2ca5480702c64c3454c
  • 1c401190a40bc5c03dc5711c57b4b416
  • 260687b5a29d9a8947d514acae695ad4
  • 3d186a44960a4edc8e297e1066e4264b
  • 6bc1aea97e7b420b0993eff794ed2aeb
  • 6e4e52cf69e37d2d540a431f23d7015a
  • 7a6e9a6e87e1e43ad188f18ae42f470f
  • 83e90ccf2523cce6dec582cdc3ddf76b
  • b61b26c9862e74772a864afcbf4feba4
  • ffad81c9cc9a6d1bd77b29c5be16d1b0
  • 192[.]69.208.202
  • 209[.]236.117.65
  • 69[.]195.129.72
  • hxxp://bestupdateserver[.]com/
  • hxxp://updateserver1[.]com
download

Tip: 25 related IOCs (3 IP, 5 domain, 2 URL, 4 email, 11 file hash) to this threat have been found.

Overlaps

Prince of PersiaDecade-Long Prince of Persia Cyber Campaign Targets Iranian Citizens and Global Victims

Source: Palo Alto Networks - June 2016

Detection (three cases): bestupdateserver[.]com, bestwebstat[.]com, updateserver1[.]com

Prince of PersiaDecade-Long Infy Malware Campaign Targets Israeli Industry and U.S. Government

Source: Palo Alto Networks - May 2016

Detection (14 cases): 0096c70453cd7110453b6609a950ce18, 1a918a850892c2ca5480702c64c3454c, 260687b5a29d9a8947d514acae695ad4, 6bc1aea97e7b420b0993eff794ed2aeb, 6e4e52cf69e37d2d540a431f23d7015a, 7a6e9a6e87e1e43ad188f18ae42f470f, aj58mail-box@yahoo[.]com, am54ja@yahoo[.]com, aminjalali_58@yahoo[.]com, bestupdateserver[.]com, bestwebstat[.]com, myblog2000[.]com, short-name[.]com, updateserver1[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Operation Mermaid

Security researchers uncovered a long-running cyber espionage campaign dubbed "Operation Mermaid." Over a period of six years, attackers successfully used deceptive emails and compromised websites to secretly install tracking software on targeted computers.

Evidence strongly suggests the attackers are a coordinated group operating out of the Middle East. Clues left behind, such as the use of the Persian language, regional usernames, and specific interest in Middle Eastern news—point directly to that region.

The primary goal of this campaign is intelligence gathering and data theft. The attackers designed their software to secretly record keystrokes, capture copied text, and monitor the daily computer activities of their victims.

The operation was highly focused but sustained over a very long period, remaining active for at least six years. Researchers have identified hundreds of malicious files and dozens of websites used to control the operation during that time.

Yes, the attackers specifically targeted government entities, most notably compromising the Ministry of Foreign Affairs of Denmark. They also focused their efforts on individuals reading specific Kurdish news outlets and targets in English- and Persian-speaking countries.

The attackers sent highly convincing emails with trapped presentation files that tricked users into allowing malicious software to run. They also infected a legitimate news website, turning it into a trap that infected visitors who simply browsed the site.

Government agencies and diplomatic offices hold highly sensitive geopolitical, economic, and strategic information. Stealing this data provides a significant intelligence advantage to the attackers or their sponsoring nation.

This is a highly targeted threat rather than a widespread issue affecting the general public. The attackers took careful measures to control who was infected and altered their software to avoid detection by common security tools.

Organizations should train staff to be highly suspicious of unexpected email attachments, especially presentation files that prompt repeated security warnings. Additionally, security teams should ensure computer protections are fully updated and restrict office documents from launching unknown programs.

About Affiliation
Mermaid
Operation Mermaid is a campaign designation for a subset of Infy cluster activity targeting Iranian opposition members and dissidents, documented through 2020. The operation used the Infy and Foudre malware families delivered via spear phishing to conduct long-term surveillance of targets including Kurdish communities and Iranian ethnic minorities. Operation Mermaid activity overlaps with the broader Prince of Persia campaign tracking by Intezer and shares the same Iranian state surveillance mission and technical infrastructure as the core Infy cluster.
View Mermaid's Insights