Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Downloader,RAT,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
In early January 2021, Proofpoint researchers identified the Iran-aligned APT actor TA451 (also known as APT33) running a spearphishing campaign against a US defense contractor using COVID-19-themed lures. The actor masqueraded as the World Health Organization, delivering emails with a link to a malicious executable named COVID19tracker[.]exe. Once a user executed the file, it reached out to download a batch script (iehchecker[.]bat), which in turn retrieved a PowerShell script (Update-KB4524147[.]ps1) with reverse shell capabilities, giving the attacker remote access to the compromised host. The campaign is documented as a case study in TA451's social engineering tradecraft within Proofpoint's broader 2022 Social Engineering Report, which covers threat actor tactics observed throughout 2021 — including multi-stage infection chains, impersonation of trusted organizations, and exploitation of topical events to lower victim defenses.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Region | United States | Verified |
FAQs
Frequently Asked Questions about TA451's COVID-19 Phishing Campaign Against US Defense
In early 2021, an Iranian state-aligned hacking group known as TA451 (also tracked as APT33) sent targeted phishing emails to employees at a US defense contractor. The emails impersonated the World Health Organization and used COVID-19 as a lure, directing recipients to click a link that downloaded malicious software. Once installed, the malware gave the attackers remote access to the victim's computer. The campaign was documented by Proofpoint researchers and published as a case study in their 2022 Social Engineering Report.
The attack was carried out by TA451, an Iranian state-aligned advanced persistent threat (APT) group also known as APT33. TA451 is assessed by multiple security vendors to operate in support of Iranian government interests. The group is known for long-running espionage campaigns against defense, energy, and government targets, primarily in the United States, Saudi Arabia, and South Korea.
The goal was espionage — gaining unauthorized remote access to systems inside a US defense contractor to collect intelligence. Once the reverse shell payload was installed, the attacker had persistent remote control over the compromised host, allowing them to run commands, move through the network, and potentially exfiltrate sensitive data related to defense programs, contracts, or personnel.
Based on the Proofpoint report, this specific campaign targeted at least one US defense contractor. TA451 is a persistent actor with a long history of targeting the defense sector across multiple countries. While this case documents a focused operation against a single organization, the group's broader campaign activity affects defense contractors, aerospace firms, and government entities across the United States and allied nations.
The primary target was the US defense sector. Defense contractors hold sensitive information about weapons systems, military technology, and government programs — exactly the type of intelligence Iran would seek for strategic and military advantage. TA451 has consistently focused on the defense and energy sectors, making US defense contractors a recurring high-priority target for the group.
The attack used a multi-stage chain. First, a phishing email impersonating the WHO prompted the target to click a link and download a file called COVID19tracker[.]exe. When executed, that file contacted attacker-controlled infrastructure to download a Windows batch script (iehchecker[.]bat). The batch script then fetched a PowerShell script (Update-KB4524147[.]ps1) that established a reverse shell — a type of remote access connection where the victim's computer reaches out to the attacker, bypassing common firewall rules. At that point, the attacker had live remote control of the compromised machine.
US defense contractors are prime targets for Iranian intelligence because they hold classified and sensitive information about military capabilities, weapons programs, and strategic planning. Gaining access to this information helps Iran assess US military readiness, anticipate potential actions, and develop countermeasures. COVID-19 was used as a lure specifically because it was universally relevant in early 2021 — people were anxious for health information and more likely to click on content appearing to come from a trusted source like the WHO.
Be highly skeptical of any email claiming to come from a health authority like the WHO, especially if it contains a link to download a file. Verify the sender's email domain carefully — legitimate WHO emails come from @who.int only. Do not execute files downloaded from email links without verifying them with your security team. Organizations should block execution of unsigned or untrusted executables, enable PowerShell and command-line logging, and monitor for outbound network connections from script interpreters. Defense contractors specifically should assume they are active targets of Iranian APT actors and enforce layered email security with URL sandboxing.