Threats Feed|APT34|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date02/02/2023

New APT34 Malware Variant Abuses Exchange Servers for Data Exfiltration

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper,Spyware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Trend Micro researchers identified a December 2022 cyberespionage campaign attributed to APT34 targeting government entities in the Middle East. The attack used a custom .NET dropper (Trojan.MSIL.REDCAP.AD) to deploy four components: a malicious Password Filter DLL (psgfilter.dll) registered into the Windows LSA to intercept plaintext credentials on every password change, a backdoor (Backdoor.MSIL.REDCAP.A) that authenticated to victim Exchange Servers using stolen credentials via Exchange Web Services (EWS), configuration files, and the Microsoft Exchange WebServices library. Stolen credentials and files were exfiltrated as email attachments through compromised government mailboxes to six external attacker-controlled addresses at Proton Mail and Gmail. The campaign's novelty lies in combining password filter abuse for persistent credential harvesting with Exchange-based exfiltration over legitimate mail traffic — a technique first observed for APT34. Hardcoded Exchange server domains and attacker email addresses inside the samples, along with code-level overlap with APT34's prior Karkoff and Saitama implants, formed the basis of attribution. Researchers noted evidence of a deep foothold across a government Active Directory forest, suggesting this was one component of a larger ongoing campaign.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Source explicitly states the campaign targeted government entities in the Middle East. Exchange servers belonging to government ministries were abused for exfiltration, and the AD domain forest across multiple government agencies was compromised.
Verified
RegionJordan
Jordan listed as one of APT34's primary targets. Prior Saitama backdoor campaign explicitly targeted a Jordanian government entity; this campaign follows the same pattern.
High
RegionSaudi Arabia
Saudi Arabia listed as one of APT34's top target countries per 2019 reporting. Consistent with this campaign's government targeting pattern in the Middle East.
High
RegionUnited Arab Emirates
UAE listed as APT34's top targeted country per 2019 intelligence reporting cited in the Trend Micro source.
High
RegionMiddle East Countries
Medium

Extracted IOCs

  • ciara.stoneburner@proton[.]me
  • earl.butler945@gmail[.]com
  • jaqueline.herrera@proton[.]me
  • kathryn.firkins@proton[.]me
  • marsha.fischer556@gmail[.]com
  • susan.potts454@proton[.]me
  • 5ed7ebc339af6ca6a5d1b9b45db6b3ae00232d9ccd80d5fcadf7680320bd4e6b
  • 827366355c6429a7fe12d111e240c5bcec3ed61e717fb84ea8b771672dd1f88e
download

Tip: 8 related IOCs (0 IP, 0 domain, 0 URL, 6 email, 2 file hash) to this threat have been found.

FAQs

APT34 Exchange Server Credential Theft Campaign — Frequently Asked Questions

In December 2022, Trend Micro identified a targeted cyberespionage campaign by APT34 against government organizations in the Middle East. The attackers deployed a custom malware package that stole user credentials — including newly changed passwords — and quietly exfiltrated sensitive files through the victims' own government email servers, making the malicious traffic blend in with normal internal mail.

The attack was carried out by APT34, an Iranian state-sponsored hacking group also known as OilRig or Helix Kitten. Active since at least 2014, APT34 is believed to operate in support of Iran's intelligence objectives, with a long history of targeting governments, financial institutions, energy companies, and telecoms across the Middle East. Trend Micro attributed this campaign to APT34 based on code similarities to prior tools (Saitama and Karkoff), overlapping infrastructure, and consistent targeting of Middle Eastern government entities.

The campaign was a credential theft and cyberespionage operation. APT34's goal was to steal user passwords — including any new passwords set after a reset — and exfiltrate sensitive files from government networks. The attack was designed to maintain persistent, covert access to government systems and communications, with strong indicators that this was part of a larger ongoing campaign against Middle Eastern government infrastructure rather than a one-off intrusion.

The campaign targeted government entities across the Middle East. Evidence from the malware samples — including hardcoded government Exchange server domains and compromised accounts found across multiple agencies — suggests the attackers had already penetrated a shared Active Directory domain forest used by several government ministries. This indicates the operation's true scope extended well beyond a single organization. APT34's historically documented top targets include the UAE, Jordan, Saudi Arabia, and a broader set of Middle Eastern countries including Qatar, Oman, Kuwait, and Bahrain.

The primary targets were government agencies and ministries in the Middle East. APT34 has a documented history of also targeting financial institutions, energy companies, chemical industries, and telecommunications providers in the region. This particular campaign was focused on the government sector, where the attackers abused internal email infrastructure — specifically Microsoft Exchange servers used by government ministries — as both a data relay and an exfiltration channel.

The attackers deployed a .NET dropper on target machines that silently installed three malicious components: a Password Filter DLL registered into Windows' authentication system to capture every plaintext password typed during a password change, a backdoor that used stolen credentials to log into the victim's Exchange email server, and supporting libraries. The backdoor then scanned a designated folder for files, packaged them as email attachments with a generic subject line to avoid suspicion, and sent them through the compromised government mailbox to six external email addresses controlled by the attackers. Because the outbound traffic looked like ordinary internal email, it was difficult for security teams to distinguish from legitimate activity.

Government organizations in the Middle East hold sensitive diplomatic, military, and economic intelligence that is highly valuable to Iranian state interests. APT34 has consistently targeted this sector for over a decade. Government Exchange servers are particularly attractive because they serve as trusted communication hubs across multiple agencies — once compromised, they provide both a rich source of intelligence and a built-in exfiltration channel that is hard to detect. The shared Active Directory trust relationships between government ministries also mean a foothold in one agency can be leveraged to access others.

Organizations should audit the LSA Notification Packages registry key (HKLM\SYSTEM\CurrentControlSet\Control\Lsa) and alert on any unexpected DLL entries. Monitor Exchange Web Services for bulk outbound email attachments originating from service accounts or unusual processes. Apply endpoint detections for the disclosed file hashes and block all email traffic to the six attacker-controlled addresses. Review and tighten Active Directory trust relationships across domain forests to limit lateral movement between agencies. Finally, enforce multi-factor authentication on Exchange and privileged accounts to reduce the impact of credential theft.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights