Imperial Kitten's Middle East Cyber Campaign: Transport and Tech Sectors Targeted
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Compromised Credentials,SQL injection,Vulnerability Exploitation,Malicious Macro,RAT,Phishing,Compromised software
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
CrowdStrike's investigation into Imperial Kitten's cyber activities reveals targeted cyberattacks and strategic web compromise (SWC) operations against transportation, logistics, and technology sectors, primarily in the Middle East. These attacks, spanning from early 2022 to 2023, involved the use of compromised websites, phishing, and malware like IMAPLoader and StandardKeyboard for initial access and persistence. Techniques such as SQL injection, the use of public exploits, and credential theft were employed. The operations leveraged tools like PAExec and NetScan for lateral movement and credential harvesting. IMPERIAL KITTEN also used custom malware and open-source tools for data exfiltration, with some utilizing Discord for command and control communications.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Information Technology | Verified |
| Sector | Logistics | Verified |
| Sector | Transportation | Verified |
| Region | Israel | Verified |
| Region | Middle East Countries | Verified |
Extracted IOCs
- blackcrocodile[.]online
- updatenewnet[.]com
- link.mymana[.]ir
- brodyheywood@yandex[.]com
- d3nisharris@yandex[.]com
- giorgosgreen@yandex[.]com
- hardi.lorel@yandex[.]com
- harri5on.patricia@yandex[.]com
- itdep@update-platform-check[.]online
- justin.w0od@yandex[.]com
- leviblum@yandex[.]com
- n0ah.harrison@yandex[.]com
- office@update-platform-check[.]online
- oliv.morris@yandex[.]com
- 1605b2aa6a911debf26b58fd3fa467766e215751377d4f746189566067dd5929
- 32c40964f75c3e7b81596d421b5cefd0ac328e01370d0721d7bfac86a2e98827
- 3bba5e32f142ed1c2f9d763765e9395db5e42afe8d0a4a372f1f429118b71446
- 5c945a2be61f1f86da618a6225bc9d84f05f2c836b8432415ff5cc13534cfe2e
- 87ccd1c15adc9ba952a07cd89295e0411b72cd4653b168f9b3f26c7a88d19b91
- 989373f2d295ba1b8750fee7cdc54820aa0cb42321cec269271f0020fa5ea006
- b588058e831d3a8a6c5983b30fc8d8aa5a711b5dfe9a7e816fe0307567073aed
- cc7120942edde86e480a961fceff66783e71958684ad1307ffbe0e97070fd4fd
- d3677394cb45b0eb7a7f563d2032088a8a10e12048ad74bae5fd9482f0aead01
- fa54988c11aa1109ff64a2ab7a7e0eeec8e4635e96f6c30950f4fbdcd2bba336
- 103[.]105.49.108
- 146[.]185.219.220
- 146[.]185.219.97
- 149[.]248.54.40
- 162[.]252.175.48
- 163[.]182.144.239
- 185[.]105.0.84
- 185[.]212.149.35
- 185[.]220.206.251
- 185[.]241.4.7
- 185[.]253.72.206
- 192[.]52.166.71
- 192[.]71.27.150
- 193[.]182.144.12
- 193[.]182.144.120
- 193[.]182.144.175
- 193[.]182.144.239
- 193[.]182.144.52
- 194[.]62.42.243
- 194[.]62.42.98
- 195[.]20.17.14
- 195[.]20.17.198
- 217[.]195.153.114
- 45[.]155.37.105
- 45[.]155.37.140
- 45[.]32.181.118
- 45[.]81.226.38
- 45[.]8.146.37
- 45[.]93.82.109
- 45[.]93.93.198
- 51[.]81.165.110
- 64[.]176.164.117
- 64[.]176.165.229
- 64[.]176.165.70
- 64[.]176.171.141
- 64[.]176.172.26
- 74[.]119.192.252
- 77[.]91.74.21
- 77[.]91.74.230
- 77[.]91.94.151
- 82[.]166.160.20
- 82[.]166.160.26
- 83[.]229.81.175
- 94[.]131.114.32
- 95[.]164.18.234
- 95[.]164.61.253
- 95[.]164.61.254
Tip: 71 related IOCs (47 IP, 3 domain, 0 URL, 11 email, 10 file hash) to this threat have been found.
Overlaps
Source: PwC - October 2023
Detection (eight cases): 32c40964f75c3e7b81596d421b5cefd0ac328e01370d0721d7bfac86a2e98827, 87ccd1c15adc9ba952a07cd89295e0411b72cd4653b168f9b3f26c7a88d19b91, 989373f2d295ba1b8750fee7cdc54820aa0cb42321cec269271f0020fa5ea006, cc7120942edde86e480a961fceff66783e71958684ad1307ffbe0e97070fd4fd, d3677394cb45b0eb7a7f563d2032088a8a10e12048ad74bae5fd9482f0aead01, brodyheywood@yandex[.]com, hardi.lorel@yandex[.]com, leviblum@yandex[.]com
Source: Cybersecurity and Infrastructure Security Agency - September 2023
Detection (one case): 103[.]105.49.108
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
IMPERIAL KITTEN Cyberespionage Campaign
In October 2023, cybersecurity researchers investigated a series of cyberattacks utilizing compromised websites and customized malicious software. Attackers lured victims to these compromised sites or sent them malicious documents to steal data and establish unauthorized access to their internal networks.
The attacks have been attributed to IMPERIAL KITTEN, a threat actor operating out of Iran. Active since at least 2017, this group is suspected of being connected to the Islamic Revolutionary Guard Corps (IRGC) and frequently uses social engineering, like fake job recruitment offers, to trick their victims.
This campaign is a strategic cyberespionage operation designed to gather intelligence. The primary goal is to profile victim systems, steal sensitive data, and maintain long-term, hidden access by using malware that blends in with normal network traffic, such as standard email and chat applications.
The campaign is geographically focused on the Middle East. Based on the compromised websites and collected data, the attacks heavily prioritize organizations located in Israel.
Yes, the attackers specifically targeted the transportation, logistics, maritime, and technology sectors. They also occasionally target IT service providers to use them as a stepping stone to reach their ultimate, primary targets.
Attackers gained initial access by exploiting software vulnerabilities, using stolen VPN logins, or tricking users into opening malicious Excel files disguised as job applications. Once inside a network, they used scanning tools to move around, stole passwords, and installed custom tools that abused regular email accounts and chat apps to secretly send stolen data back to the attackers.
Organizations in these specific sectors likely hold valuable strategic, logistical, or technological data. Stealing this information fulfills the strategic intelligence requirements of the Iranian government and associated military operations.
Organizations should secure their remote access points like VPNs, apply software updates to fix known vulnerabilities, and monitor their networks for unexpected connections to email or chat services. Individuals should remain highly cautious of unsolicited job recruitment documents or emails that ask them to enable macros.
This is a highly targeted campaign rather than a widespread issue. The threat actors carefully select specific industries in the Middle East and actively profile website visitors to ensure they are only infecting their desired targets.