PowerExchange Campaign: APT34's Persistent Threat to UAE Government
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,Phishing
- Attack Complexity: Medium
- Threat Risk: Unknown
Threat Overview
The PowerExchange campaign, attributed to APT34, targeted Microsoft Exchange servers of a UAE government entity using a PowerShell backdoor. Delivered via phishing emails, the backdoor used the MicrosoftEdgeUpdateService for persistence, enabling frequent execution. The attackers used the Exchange Web Services API for command-and-control, deploying further payloads like Invoke-TheHash modules for lateral movement and webshells for credential harvesting.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | United Arab Emirates | Verified |
FAQs
The PowerExchange Backdoor Campaign
Cybersecurity researchers have rediscovered a sophisticated cyberattack campaign targeting Microsoft Exchange servers. The attackers utilized a custom-built piece of malware, known as the "PowerExchange" backdoor, to gain unauthorized access and steal information.
The attack has been attributed to APT34, a known Iranian threat actor. Researchers linked this current activity to the group by comparing it to the tactics used in their July 2018 "xHunt" campaign, which previously targeted organizations in Kuwait.
This specific campaign was highly targeted, focusing on the Microsoft Exchange servers of an unidentified government entity located in the United Arab Emirates (UAE).
The attack began with a deceptive phishing email containing a malicious file. Once a user activated it, the malware installed itself and created a fake "Microsoft Edge Update" task to keep itself running continuously in the background.
The primary goal of the attack was cyber espionage. Once inside the system, the attackers used the backdoor to deploy additional tools designed to steal user passwords, move deeper into the network, and secretly extract sensitive data.
The attackers cleverly used the target's own email system against them. The malware received its instructions via hidden text within email attachments and sent stolen data back to the attackers disguised as routine Microsoft Edge update emails.
Organizations should rigorously scan for deceptive phishing emails and monitor their systems for fake scheduled tasks, specifically those impersonating Microsoft Edge updates. Security teams should also apply the provided threat-hunting rules to search their networks for the specific files used in this attack.