Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Compromised Credentials,Backdoor,Keylogger,Malware,Trojan,Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Crambus launched a sophisticated attack involving multiple malware strains, including three new ones: Tokel, Dirps, and Infostealer.Clipog, along with the known PowerExchange backdoor. The malware provided a wide range of functionalities from executing arbitrary PowerShell commands to information stealing and email monitoring. Living-off-the-land tools like Mimikatz and Plink were also deployed to dump credentials and configure port-forwarding for RDP access, respectively. The attackers displayed an advanced level of evasion, execution, and command-and-control techniques. The malicious activities spanned over several months, indicating a well-coordinated and persistent attack strategy.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Albania | High |
| Region | Iraq | High |
| Region | Israel | High |
| Region | Jordan | High |
| Region | Kuwait | High |
| Region | Lebanon | High |
| Region | Qatar | High |
| Region | Saudi Arabia | High |
| Region | Turkey | High |
| Region | United Arab Emirates | High |
| Region | United States | High |
Extracted IOCs
- 159b07668073e6cd656ad7e3822db997d5a8389a28c439757eb60ba68eaff70f
- 1698f9797f059c4b30f636d16528ed3dd2b4f8290e67eb03e26181e91a3d7c3b
- 22df38f5441dec57e7d7c2e1a38901514d3f55203b2890dc38d2942f1e4bc100
- 23db83aa81de19443cafe14c9c0982c511a635a731d6df56a290701c83dae9c7
- 41672b08e6e49231aedf58123a46ed7334cafaad054f2fd5b1e0c1d5519fd532
- 41ff7571d291c421049bfbd8d6d3c51b0a380db3b604cef294c1edfd465978d9
- 497978a120f1118d293906524262da64b15545ee38dc0f6c10dbff3bd9c0bac2
- 497e1c76ed43bcf334557c64e1a9213976cd7df159d695dcc19c1ca3d421b9bc
- 4d04ad9d3c3abeb61668e52a52a37a46c1a60bc8f29f12b76ff9f580caeefba8
- 5a803bfe951fbde6d6b23401c4fd1267b03f09d3907ef83df6cc25373c11a11a
- 661c9535d9e08a3f5e8ade7c31d5017519af2101786de046a4686bf8a5a911ff
- 6964f4c6fbfb77d50356c2ee944f7ec6848d93f05a35da6c1acb714468a30147
- 6b9f60dc91fbee3aecb4a875e24af38c97d3011fb23ace6f34283a73349c4681
- 6bad09944b3340947d2b39640b0e04c7b697a9ce70c7e47bc2276ed825e74a2a
- 75878356f2e131cefb8aeb07e777fcc110475f8c92417fcade97e207a94ac372
- 7e107fdd6ea33ddc75c1b75fdf7a99d66e4739b4be232ff5574bf0e116bc6c05
- 927327bdce2f577b1ee19aa3ef72c06f7d6c2ecd5f08acc986052452a807caf2
- a1a633c752be619d5984d02d4724d9984463aa1de0ea1375efda29cadb73355a
- a6365e7a733cfe3fa5315d5f9624f56707525bbf559d97c66dbe821fae83c9e9
- ba620b91bef388239f3078ecdcc9398318fd8465288f74b4110b2a463499ba08
- be6d631fb2ff8abe22c5d48035534d0dede4abfd8c37b1d6cbf61b005d1959c1
- c3ac52c9572f028d084f68f6877bf789204a6a0495962a12ee2402f66394a918
- c488127b3384322f636b2a213f6f7b5fdaa6545a27d550995dbf3f32e22424bf
- d0bfdb5f0de097e4460c13bc333755958fb30d4cb22e5f4475731ad1bdd579ec
- d884b3178fc97d1077a13d47aadf63081559817f499163c2dc29f6828ee08cae
- db1cbe1d85a112caf035fd5d4babfb59b2ca93411e864066e60a61ec8fe27368
- 151[.]236.19.91
- 78[.]47.218.106
- 91[.]132.92.90
Tip: 29 related IOCs (3 IP, 0 domain, 0 URL, 0 email, 26 file hash) to this threat have been found.
FAQs
Crambus Campaign Targeting Middle Eastern Government
Over an eight-month period, attackers compromised multiple computers and servers belonging to a Middle Eastern government. The intruders stole files, captured passwords, and deployed hidden software to secretly monitor communications and execute commands on the network. They managed to compromise at least 12 core computers and likely deployed tools on dozens more.
The attack was carried out by a well-known Iranian espionage group known as Crambus, which is also tracked under the names OilRig and APT34. This group is highly experienced and frequently stages long-term intrusions for intelligence gathering and spying purposes. They have a deep history of targeting entities in the Middle East and surrounding regions.
The primary goal of the attack was cyber espionage and intelligence gathering. The attackers sought to maintain a quiet, long-term presence on the network to steal sensitive files, log keystrokes, and extract user credentials without being detected.
The attack was highly persistent and embedded deep within the targeted organization. The attackers maintained access for at least eight months, directly compromising a dozen servers and computers, including highly sensitive systems, while placing backdoors and keyloggers on many other machines.
Yes, this specific campaign was aimed directly at a government entity in the Middle East. The Crambus group traditionally targets governments and large organizations that are of geopolitical interest to Iran, often seeking sensitive state data or internal communications.
The attackers initially gained access and executed malicious scripts to establish a foothold. They relied heavily on legitimate remote access tools and specialized software hidden within the organization's internal email server to receive instructions secretly. They continuously mapped the network, stole passwords, and altered system settings to allow remote access to other computers.
Government entities handle highly sensitive political, diplomatic, and economic information. Because Crambus is a state-aligned espionage group, targeting regional governments provides valuable strategic intelligence that aligns with the geopolitical interests of their state sponsors.
Organizations should actively monitor their networks for unusual administrative tool usage or unexpected remote desktop connections. It is critical to regularly audit email server rules for suspicious filtering, hunt for unauthorized network scanning, and implement robust defenses against credential theft.
This specific incident was a highly targeted campaign against a single government entity. However, the Crambus group's ongoing activities show that they remain a continuous threat to various organizations, demonstrating that organizations in the region must remain on high alert.