Threats Feed|ITG07|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date14/06/2019

Unveiling TREKX: ITG07's Weapon of Choice for Intrusion in the Transportation Sector

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Compromised Credentials,Vulnerability Exploitation,Backdoor,RAT,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/High Probability

Threat Overview

IBM X-Force researchers documented a sustained intrusion campaign by ITG07 — also tracked as Chafer and APT39 — targeting transportation sector organizations across multiple countries from at least September 2018 through mid-2019. The attackers gained initial footholds by exploiting public-facing applications and deploying webshells (JSPSPY, ASPXSPY), then moved laterally using stolen credentials harvested with a customized version of Mimikatz and legitimate remote access tools including Citrix and PsExec. A previously undocumented custom remote access trojan named TREKX was used to maintain persistent backdoor access. Microsoft BITS was abused for stealthy file transfer and data exfiltration. Internal reconnaissance was conducted using NBTscan. The campaign demonstrated a high level of operational sophistication, combining custom malware with living-off-the-land techniques to avoid detection.

Detected Targets

TypeDescriptionConfidence
SectorTransportation
The transportation sector was targeted by the attack.
Verified

Extracted IOCs

  • nvidia-services[.]com
  • sabre-airlinesolutions[.]com
  • sabre-css[.]com
  • 01e4391421d56698bcaa1f3c05bd9818
  • 405506980d6057a0b1c756e3c67641a0
  • 7c08601341888b413779a3b33d8bf6dc
  • 7fac7a0843f65135832ac5685750cc6c
  • ade5518c61a620c5e3b226ce3c84e7af
  • cec4bb3b2f4d2ca2f3468103efb5967d
  • cf7d3e9ca78ab23929e94215d871bd51
  • d0e74da12c5e8d35f6db1ae0c60748b7
  • ede89b446d8703dd13d26168e8d58865
  • f01a9a2d1e31332ed36c1a4d2839f412
download

Tip: 13 related IOCs (0 IP, 3 domain, 0 URL, 0 email, 10 file hash) to this threat have been found.

Overlaps

ChaferThe Invisible Threat: Chafer's Advanced Backdoor Malware Analysis

Source: NCC Group - March 2019

Detection (two cases): nvidia-services[.]com, sabre-css[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: ITG07's TREKX Campaign Against the Transportation Sector

IBM X-Force researchers uncovered a prolonged cyber-espionage campaign by the Iran-linked group ITG07 — also known as Chafer and APT39 — targeting transportation companies across multiple countries. The attackers used a combination of custom malware, stolen credentials, and legitimate system tools to infiltrate networks, move laterally, and maintain persistent access over a period stretching from at least September 2018 through mid-2019. A previously unknown custom remote access trojan called TREKX was identified as a central tool in the operation.

The attack was carried out by ITG07, IBM's designation for the threat group also known as Chafer (Symantec) and APT39 (Mandiant). This is an Iran-based cyber-espionage actor with a history of targeting transportation, telecommunications, and other strategic sectors. Attribution is supported by the use of tools and techniques consistent with known Chafer operations, including BITS-based exfiltration, customized Mimikatz, and webshell deployment. Shared IOC overlap with a separate Chafer report further corroborates this attribution.

This was a cyber-espionage campaign focused on gaining deep, persistent access to transportation sector networks in order to collect intelligence. The attackers were not seeking immediate disruption — they aimed to stay undetected for as long as possible, moving laterally through victim environments, harvesting credentials, and exfiltrating data. The use of a custom RAT, multiple persistence mechanisms, and living-off-the-land techniques reflects a deliberate effort to conduct long-term surveillance rather than a quick smash-and-grab operation.

The campaign was geographically broad, targeting transportation organizations across multiple countries. IBM described the victims as "geographically dispersed," indicating this was not limited to a single region. The operation ran for at least nine months — from September 2018 through at least June 2019 — and involved multiple victim organizations, suggesting a systematic effort to compromise the transportation sector rather than a single targeted intrusion.

The primary targets were organizations in the transportation sector — including companies linked to aviation, as suggested by the use of lookalike domains mimicking Sabre, a major airline technology provider (sabre-css.com, sabre-airlinesolutions.com), and an NVIDIA-branded domain. The attackers also targeted database systems using Navicat, suggesting interest in operational and passenger data held by transportation companies.

The attackers gained initial access by exploiting vulnerabilities in internet-facing applications and deploying webshells (JSPSPY, ASPXSPY) on compromised servers. Once inside, they harvested credentials using a customized version of Mimikatz and LLMNR poisoning techniques, then moved laterally using RDP, PsExec, and SSH tunneling tools (Plink, RemCom). The TREKX RAT was deployed to maintain persistent backdoor access, while Microsoft BITS was abused to quietly transfer tools and exfiltrate data. Internal network scanning with NBTscan helped map victim environments for further exploitation.

Transportation companies — particularly airlines and logistics operators — hold highly sensitive data including passenger manifests, travel itineraries, cargo records, and operational schedules. For an intelligence service, this data can reveal the movements of government officials, military personnel, and persons of interest. Aviation technology vendors like Sabre also provide access to reservation systems used by airlines globally, making them high-value targets for broad intelligence collection. The sector's reliance on interconnected IT systems also makes lateral movement easier once initial access is achieved.

Audit internet-facing servers for webshell presence, especially in web application directories. Monitor BITS job activity for unexpected outbound transfers, and restrict or alert on `bitsadmin.exe` usage where not operationally required. Block or monitor LLMNR and NBT-NS traffic at the network level to prevent credential interception. Review Citrix and RDP access logs for anomalous login activity. Deploy endpoint detection tools capable of identifying TREKX, customized Mimikatz variants, and known webshell signatures. Transportation companies with global operations and aviation technology vendors should treat ITG07 as a current, elevated threat.

About Affiliation
ITG07
ITG07 is IBM X-Force's designation for the Iranian threat cluster known as APT39. Active since at least 2014, the group focuses on espionage and personal information theft targeting telecommunications, travel, and government organizations. IBM's tracking of this cluster aligns closely with Mandiant's APT39 and Symantec's Chafer reporting, covering the same TTPs: spear phishing, web shell deployment, custom backdoor usage, and large-scale data collection. The cluster is assessed to operate in support of Iranian state surveillance interests.
View ITG07's Insights