Mermaid APT: A Continuing Threat to Government Agencies
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Keylogger,Trojan,Phishing
- Attack Complexity: Medium
- Threat Risk: Unknown
Threat Overview
The Mermaid (Infy, Prince of Persia) APT organization, primarily targeting government agencies, has been active since 2010 with consistent attacks and no significant operational gaps. Originating from the Middle East, they utilize the Infy backdoor, evolving into the Foudre backdoor by 2017. The group employs documents with malicious macros, embedding OLE objects to execute the Foudre backdoor via social engineering. Techniques include keylogging, registry modification, scheduled tasks for persistence, and using rundll32 for process injection. The attack also involves substantial data concealment with compressed files and web protocol communication for C2 interactions. The report indicates a sophisticated approach in both evading detection and maintaining long-term access to targeted systems.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
Extracted IOCs
- 00e9ce3d[.]space
- 035ade4d[.]space
- 07840a24[.]space
- 08aa2c3f[.]space
- 095f8216[.]space
- 0a71ab21[.]space
- 0d1c6f38[.]space
- 1044b357[.]space
- 1058831c[.]space
- 12bbd9fe[.]space
- 149a673e[.]space
- 15d61de7[.]space
- 19154751.space
- 19eecf37[.]space
- 19f2ff7c[.]space
- 19f7493f[.]space
- 1b857d83[.]space
- 1bd59ba3[.]space
- 1cb85fba[.]space
- 1ce8b99a[.]space
- 1e788348[.]space
- 1e9a8d26[.]space
- 1e9f3b65[.]space
- 207e70f8[.]space
- 21bc1acf[.]space
- 2238cea1[.]space
- 226ee19e[.]space
- 25550ab8[.]space
- 26d1ded6[.]space
- 2713b4e1[.]space
- 2ae05df2[.]space
- 2bd8adb5[.]space
- 2d8d99eb[.]space
- 310860a4[.]space
- 32370d70[.]space
- 328cb4ca[.]space
- 32c39cf4[.]space
- 32dfacbf[.]space
- 334edefd[.]space
- 34231ae4[.]space
- 355ac969[.]space
- 35b268a6[.]space
- 35e170d3[.]space
- 3665a4bd[.]space
- 3b69e094[.]space
- 3b75d0df[.]space
- 3c573cf8[.]space
- 3d9556cf[.]space
- 3fd3e896[.]space
- 4162942b[.]space
- 425df9ff[.]space
- 42a9687b[.]space
- 42e64045[.]space
- 43242a72[.]space
- 4449ee6b[.]space
- 45303de6[.]space
- 458b845c[.]space
- 45c4ac62[.]space
- 45d89c29[.]space
- 460f5032[.]space
- 48d4d800[.]space
- 4a926659[.]space
- 4b500c6e[.]space
- 4c6ed002[.]space
- 4c72e049[.]space
- 50148477.space
- 51d6ee40[.]space
- 52523a2e[.]space
- 553ffe37[.]space
- 5569d108[.]space
- 56bb2a59[.]space
- 5779406e[.]space
- 5a8aa97d[.]space
- 5bb2593a[.]space
- 5cdf9d23[.]space
- 5de76d64[.]space
- 62d12d71[.]space
- 639d57a8[.]space
- 65bce968[.]space
- 674383c1[.]space
- 675fb38a[.]space
- 697fb3de[.]space
- 69843bb8[.]space
- 699dbdb0[.]space
- 6bbf6f2c[.]space
- 6bef890c[.]space
- 6c824d15[.]space
- 6cd2ab35[.]space
- 6e1277c7[.]space
- 6ee9ffa1[.]space
- 6ef079a9[.]space
- 6ef5cfea[.]space
- 761b5082[.]space
- 77eefeab[.]space
- 7a1b5fae[.]space
- 7d769bb7[.]space
- 7e58b280[.]space
- 7e6f769e[.]space
- 801c16eb[.]space
- 80e79e8d[.]space
- 80fbaec6[.]space
- 80fe1885[.]space
- 828c2c39[.]space
- 82dcca19[.]space
- 85690076.space
- 85b10e00[.]space
- 85e1e820[.]space
- 8771d2f2[.]space
- 878a5a94[.]space
- 8793dc9c[.]space
- 87966adf[.]space
- 8b3a6012[.]space
- 8b6a8632[.]space
- 8bb28844[.]space
- 8cdf4c5d[.]space
- 8d933684[.]space
- 8e2590b7[.]space
- 8ec79ed9[.]space
- 91a37d85[.]space
- 9378fa9b[.]space
- 94153e82[.]space
- 99e09f87[.]space
- 9aceb6b0[.]space
- 9e8d5b9e[.]space
- a28810e1[.]space
- a801311e[.]space
- aa478f47[.]space
- ab3e5cca[.]space
- ab85e570[.]space
- abcacd4e[.]space
- abd6fd05[.]space
- aca70957[.]space
- acbb391c[.]space
- ace82169[.]space
- ad2a4b5e[.]space
- af6cf507[.]space
- b0c16d69[.]space
- b103075e[.]space
- b287d330[.]space
- b2d1fc0f[.]space
- b3e90c48[.]space
- b484c851[.]space
- b5bc3816[.]space
- b8b54b75[.]space
- b9772142[.]space
- ba5f4063[.]space
- bb319f1b[.]space
- bc5c5b02[.]space
- be1ae55b[.]space
- bfd88f6c[.]space
- c2bb0880[.]space
- c383f8c7[.]space
- c4ee3cde[.]space
- c580e3a6[.]space
- c5d6cc99[.]space
- c60437c8[.]space
- c7c65dff[.]space
- c8dfbffa[.]space
- c91dd5cd[.]space
- cb5b6b94[.]space
- cc36af8d[.]space
- cd5870f5[.]space
- ce7011d4[.]space
- cfb27be3[.]space
- d58f2077[.]space
- d86bc591[.]space
- da2d7bc8[.]space
- db54a845[.]space
- dba039c1[.]space
- dbbc098a[.]space
- dbef11ff[.]space
- dc396c5c[.]space
- dc82d5e6[.]space
- dccdfdd8[.]space
- dcd1cd93[.]space
- dd40bfd1[.]space
- df060188[.]space
- e00be33d[.]space
- e47fca0d[.]space
- e6a44d13[.]space
- e98a6b08[.]space
- edc98626[.]space
- eee7af11[.]space
- f076e264[.]space
- f08d6a02[.]space
- f0915a49[.]space
- f094ec0a[.]space
- f26e30e0[.]space
- f2b63e96[.]space
- f2e6d8b6[.]space
- f58b1caf[.]space
- f5dbfa8f[.]space
- f7e0ae1b[.]space
- f7f92813[.]space
- f7fc9e50[.]space
- f922a021[.]space
- f9c0ae4f[.]space
- fbd87ccb[.]space
- fc3d5084[.]space
- fc6db6a4[.]space
- 1a46bd6385feae53a6b8aed758e16556
- 2c111a27d0d9d48e9470264b4c16b472
- 4381a0c76f2bff772063e6cc6a1ac876
- 8b8e286f64a4635e12d6d728a5669d51
- 916e3d4c5835380c99efa802ddb4436d
- be11401b723ec4f20be8d65c04a8003e
- d497e0332e88341bd5ddbaa326cab977
- dc14f029efa635d5922012904e162808
Tip: 208 related IOCs (0 IP, 200 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.
Overlaps
Source: Checkpoint - February 2021
Detection (eight cases): 07840a24[.]space, 1e9f3b65[.]space, 35b268a6[.]space, 42a9687b[.]space, 5bb2593a[.]space, 69843bb8[.]space, 801c16eb[.]space, 8bb28844[.]space
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Mermaid (FoudreAPT) Attack Campaign
Security researchers recently uncovered a new cyberattack campaign utilizing malicious documents to deliver malware. The attackers used hidden programs within document files to secretly install updated versions of a backdoor known as "Foudre" (versions 21 and 22) onto victim computers.
The attack was carried out by a Middle Eastern threat group known as Mermaid, which is also referred to by researchers as infy, Prince of Persia, or FoudreAPT. This group is a well-established threat organization that has been conducting cyber operations since 2010.
The primary goal of this attack is cyber espionage and unauthorized data collection. Once the attackers successfully compromise a computer, they install keylogging software to record what the user types and establish a hidden connection to download additional malicious tools.
Yes, the Mermaid organization primarily targets government agencies. They use social engineering—tricking specific individuals into opening harmful files, to gain a foothold into these high-value networks.
Attackers sent victims documents containing hidden, malicious code (macros). When a victim opened the document, the code automatically extracted a hidden file, bypassed the computer's antivirus software by artificially inflating its file size, and set itself up to run automatically every time the user logged in.
Government agencies are highly attractive targets for foreign threat actors because they hold sensitive intelligence, strategic communications, and confidential data that can be used for international espionage and geopolitical advantage.
Organizations should disable untrusted macros in document files and educate staff on the dangers of opening unsolicited attachments. Additionally, IT teams should ensure their antivirus software is updated to detect file-padding tricks and monitor for unauthorized background tasks.
This is a highly targeted issue. The threat actors are specifically aiming at government agencies rather than conducting widespread, random attacks against the general public.