Iranian Attack Group's Phishing Campaign Targets Israeli Economy with F5 Impersonation
- Actor Motivations: Espionage,Sabotage
- Attack Vectors: Dropper,Malware,Spyware,Wiper,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
In December, an Iranian attack group launched a phishing campaign impersonating F5 company to target Israeli economic sectors. The campaign aimed for destructive attacks and information gathering. It involved emails from a spoofed F5 address, containing links to download Wiper and Infostealer malware. The attack exploited an F5 critical warning, requiring users to run a Shell Script file. Malicious files included a .NET-based f5updater.exe for Windows and a Bash Script for Linux. These scripts, effective only with administrative privileges, were designed for data destruction and information stealing, with the latter employing advanced evasion techniques like AV service disabling and script obfuscation.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Financial | Verified |
| Region | Israel | Verified |
Extracted IOCs
- f5[.]support
- cert@f5[.]support
- 04ca69ec86453bdea484e1c1edc3f883
- 08efd480e2c105382ba277a905f0c4a9
- 2783376fd7af9ec138ecf49ad7391f16
- 2ff97de7a16519b74113ea9137c6ba0c
- 684c60b649df7786eafe2ead68d84565
- 8678cca1ee25121546883db16846878b
- 8bdd1cb717aa2bd03c12c8b4c9df2d94
- 8f69c9bb80b210466b887d2b16c68600
- 3a05a0238f892e53112654bf136ef352e7476a9b
- 5def5e492435cfd423e51515925d17285b77cdbc
- 7cf41af145f19e5af9a1ace48323cffe09c0aedf
- b57a6098e56961f1800c9d485117e9a7cd4eeddd
- db38eeb9490cc7946b3ed0cf3759acb41666bdc3
- ff591e66a580d043afc70d86bdf8588e369f890b
- 64c5fd791ee369082273b685f724d5916bd4cad756750a5fe953c4005bb5428c
- 6f79c0e0e1aab63c3aba0b781e0e46c95b5798b2d4f7b6ecac474b5c40b840ad
- ad66251d9e8792cf4963b0c97f7ab44c8b68101e36b79abc501bee1807166e8a
- ca9bf13897af109cb354f2629c10803966eb757ee4b2e468abc04e7681d0d74a
- e28085e8d64bb737721b1a1d494f177e571c47aab7c9507dba38253f6183af35
- fe07dca68f288a4f6d7cbd34d79bb70bc309635876298d4fde33c25277e30bd2
Tip: 22 related IOCs (0 IP, 1 domain, 0 URL, 1 email, 20 file hash) to this threat have been found.
Overlaps
Source: Cyberint - July 2024
Detection (eight cases): 64c5fd791ee369082273b685f724d5916bd4cad756750a5fe953c4005bb5428c, 6f79c0e0e1aab63c3aba0b781e0e46c95b5798b2d4f7b6ecac474b5c40b840ad, 8bdd1cb717aa2bd03c12c8b4c9df2d94, 8f69c9bb80b210466b887d2b16c68600, ad66251d9e8792cf4963b0c97f7ab44c8b68101e36b79abc501bee1807166e8a, ca9bf13897af109cb354f2629c10803966eb757ee4b2e468abc04e7681d0d74a, e28085e8d64bb737721b1a1d494f177e571c47aab7c9507dba38253f6183af35, fe07dca68f288a4f6d7cbd34d79bb70bc309635876298d4fde33c25277e30bd2
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
F5 Impersonation Phishing Campaign
In December, a deceptive email campaign was discovered masquerading as official security alerts from the technology company F5. The emails tricked users into downloading malicious files disguised as critical software updates. Once downloaded and run, these files installed malicious software designed to steal data and permanently delete files on the organization's servers.
Authorities have attributed this cyberattack to an Iranian threat group. These attackers are known for conducting thorough background research on their targets, going so far as to find the specific internet addresses of the victim's hardware to make their fake emails look highly credible.
The campaign has two primary goals: stealing sensitive information and causing widespread destruction. The attackers use "Infostealer" software to quietly gather intelligence from the network and "Wiper" software to permanently erase the compromised servers, causing significant operational damage.
The campaign is specifically aimed at organizations within the Israeli economy. The attacks were executed in a coordinated manner, occurring in two distinct waves sent within 72 hours of each other.
The campaign targeted organizations in Israel that utilize F5 networking equipment. The emails were aimed specifically at IT personnel and system administrators, as the malicious software requires high-level administrative access to successfully run and destroy the network servers.
Attackers sent fake emails claiming the recipient needed to urgently download a fix for a known vulnerability. Because the malware cannot spread on its own, the attackers relied on the tricked IT administrators to manually copy and run the fake update across their organization's servers. Once run, the software stole data, sent it to the attackers via the Telegram messaging app, and then attempted to wipe the machines.
Organizations using enterprise-level F5 equipment often manage large networks and hold valuable intellectual property or sensitive data. Targeting these entities within the Israeli economy aligns with the attacker group's objective to gather foreign intelligence and cause disruptive financial and operational damage.
Organizations should verify all security alerts by checking directly with the vendor rather than clicking links in emails. IT administrators must be warned that official F5 support emails come from "F5SIRT@f5.com", not "cert@f5.support", and user accounts should have their administrative privileges restricted to limit the damage if a malicious file is accidentally opened.
This is a highly targeted and sophisticated campaign. The attackers customized the phishing emails for each specific victim and created unique download links for every target, making it difficult for standard security systems to detect a widespread pattern.