Threats Feed|TA451|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date15/06/2022

Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Downloader,RAT,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

In early January 2021, Proofpoint researchers identified the Iran-aligned APT actor TA451 (also known as APT33) running a spearphishing campaign against a US defense contractor using COVID-19-themed lures. The actor masqueraded as the World Health Organization, delivering emails with a link to a malicious executable named COVID19tracker[.]exe. Once a user executed the file, it reached out to download a batch script (iehchecker[.]bat), which in turn retrieved a PowerShell script (Update-KB4524147[.]ps1) with reverse shell capabilities, giving the attacker remote access to the compromised host. The campaign is documented as a case study in TA451's social engineering tradecraft within Proofpoint's broader 2022 Social Engineering Report, which covers threat actor tactics observed throughout 2021 — including multi-stage infection chains, impersonation of trusted organizations, and exploitation of topical events to lower victim defenses.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified
RegionUnited States
Verified

FAQs

Frequently Asked Questions about TA451's COVID-19 Phishing Campaign Against US Defense

In early 2021, an Iranian state-aligned hacking group known as TA451 (also tracked as APT33) sent targeted phishing emails to employees at a US defense contractor. The emails impersonated the World Health Organization and used COVID-19 as a lure, directing recipients to click a link that downloaded malicious software. Once installed, the malware gave the attackers remote access to the victim's computer. The campaign was documented by Proofpoint researchers and published as a case study in their 2022 Social Engineering Report.

The attack was carried out by TA451, an Iranian state-aligned advanced persistent threat (APT) group also known as APT33. TA451 is assessed by multiple security vendors to operate in support of Iranian government interests. The group is known for long-running espionage campaigns against defense, energy, and government targets, primarily in the United States, Saudi Arabia, and South Korea.

The goal was espionage — gaining unauthorized remote access to systems inside a US defense contractor to collect intelligence. Once the reverse shell payload was installed, the attacker had persistent remote control over the compromised host, allowing them to run commands, move through the network, and potentially exfiltrate sensitive data related to defense programs, contracts, or personnel.

Based on the Proofpoint report, this specific campaign targeted at least one US defense contractor. TA451 is a persistent actor with a long history of targeting the defense sector across multiple countries. While this case documents a focused operation against a single organization, the group's broader campaign activity affects defense contractors, aerospace firms, and government entities across the United States and allied nations.

The primary target was the US defense sector. Defense contractors hold sensitive information about weapons systems, military technology, and government programs — exactly the type of intelligence Iran would seek for strategic and military advantage. TA451 has consistently focused on the defense and energy sectors, making US defense contractors a recurring high-priority target for the group.

The attack used a multi-stage chain. First, a phishing email impersonating the WHO prompted the target to click a link and download a file called COVID19tracker[.]exe. When executed, that file contacted attacker-controlled infrastructure to download a Windows batch script (iehchecker[.]bat). The batch script then fetched a PowerShell script (Update-KB4524147[.]ps1) that established a reverse shell — a type of remote access connection where the victim's computer reaches out to the attacker, bypassing common firewall rules. At that point, the attacker had live remote control of the compromised machine.

US defense contractors are prime targets for Iranian intelligence because they hold classified and sensitive information about military capabilities, weapons programs, and strategic planning. Gaining access to this information helps Iran assess US military readiness, anticipate potential actions, and develop countermeasures. COVID-19 was used as a lure specifically because it was universally relevant in early 2021 — people were anxious for health information and more likely to click on content appearing to come from a trusted source like the WHO.

Be highly skeptical of any email claiming to come from a health authority like the WHO, especially if it contains a link to download a file. Verify the sender's email domain carefully — legitimate WHO emails come from @who.int only. Do not execute files downloaded from email links without verifying them with your security team. Organizations should block execution of unsigned or untrusted executables, enable PowerShell and command-line logging, and monitor for outbound network connections from script interpreters. Defense contractors specifically should assume they are active targets of Iranian APT actors and enforce layered email security with URL sandboxing.

About Affiliation
TA451
TA451 is Proofpoint's tracking designation for the Iranian state-sponsored threat cluster widely known as APT33 and Elfin, linked to the IRGC and active since at least 2013. The group conducts cyber espionage primarily against aviation, energy, defense, government, and healthcare organizations in Saudi Arabia, South Korea, and the United States, using spear phishing with job-recruitment lures and malicious HTA files for initial access. In documented campaigns, TA451 has targeted US defense contractor personnel and aerospace-sector employees in the UAE using HTA files delivered via targeted business-to-business sales approaches. Proofpoint documented TA451 as active through at least December 2019 in public reporting, though APT33 campaign activity has continued under other vendor designations. The group is separately tracked as Peach Sandstorm (Microsoft), Refined Kitten (CrowdStrike), and Magnallium (Dragos), and is widely suspected in connection with the Shamoon wiper attacks against Saudi Aramco.
View TA451's Insights