Threats Feed|Crambus|Last Updated 07/07/2026|AuthorCertfa Radar|Publish Date19/10/2023

Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Compromised Credentials,Backdoor,Keylogger,Malware,Trojan,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Crambus launched a sophisticated attack involving multiple malware strains, including three new ones: Tokel, Dirps, and Infostealer.Clipog, along with the known PowerExchange backdoor. The malware provided a wide range of functionalities from executing arbitrary PowerShell commands to information stealing and email monitoring. Living-off-the-land tools like Mimikatz and Plink were also deployed to dump credentials and configure port-forwarding for RDP access, respectively. The attackers displayed an advanced level of evasion, execution, and command-and-control techniques. The malicious activities spanned over several months, indicating a well-coordinated and persistent attack strategy.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionAlbania
High
RegionIraq
High
RegionIsrael
High
RegionJordan
High
RegionKuwait
High
RegionLebanon
High
RegionQatar
High
RegionSaudi Arabia
High
RegionTurkey
High
RegionUnited Arab Emirates
High
RegionUnited States
High

Extracted IOCs

  • 159b07668073e6cd656ad7e3822db997d5a8389a28c439757eb60ba68eaff70f
  • 1698f9797f059c4b30f636d16528ed3dd2b4f8290e67eb03e26181e91a3d7c3b
  • 22df38f5441dec57e7d7c2e1a38901514d3f55203b2890dc38d2942f1e4bc100
  • 23db83aa81de19443cafe14c9c0982c511a635a731d6df56a290701c83dae9c7
  • 41672b08e6e49231aedf58123a46ed7334cafaad054f2fd5b1e0c1d5519fd532
  • 41ff7571d291c421049bfbd8d6d3c51b0a380db3b604cef294c1edfd465978d9
  • 497978a120f1118d293906524262da64b15545ee38dc0f6c10dbff3bd9c0bac2
  • 497e1c76ed43bcf334557c64e1a9213976cd7df159d695dcc19c1ca3d421b9bc
  • 4d04ad9d3c3abeb61668e52a52a37a46c1a60bc8f29f12b76ff9f580caeefba8
  • 5a803bfe951fbde6d6b23401c4fd1267b03f09d3907ef83df6cc25373c11a11a
  • 661c9535d9e08a3f5e8ade7c31d5017519af2101786de046a4686bf8a5a911ff
  • 6964f4c6fbfb77d50356c2ee944f7ec6848d93f05a35da6c1acb714468a30147
  • 6b9f60dc91fbee3aecb4a875e24af38c97d3011fb23ace6f34283a73349c4681
  • 6bad09944b3340947d2b39640b0e04c7b697a9ce70c7e47bc2276ed825e74a2a
  • 75878356f2e131cefb8aeb07e777fcc110475f8c92417fcade97e207a94ac372
  • 7e107fdd6ea33ddc75c1b75fdf7a99d66e4739b4be232ff5574bf0e116bc6c05
  • 927327bdce2f577b1ee19aa3ef72c06f7d6c2ecd5f08acc986052452a807caf2
  • a1a633c752be619d5984d02d4724d9984463aa1de0ea1375efda29cadb73355a
  • a6365e7a733cfe3fa5315d5f9624f56707525bbf559d97c66dbe821fae83c9e9
  • ba620b91bef388239f3078ecdcc9398318fd8465288f74b4110b2a463499ba08
  • be6d631fb2ff8abe22c5d48035534d0dede4abfd8c37b1d6cbf61b005d1959c1
  • c3ac52c9572f028d084f68f6877bf789204a6a0495962a12ee2402f66394a918
  • c488127b3384322f636b2a213f6f7b5fdaa6545a27d550995dbf3f32e22424bf
  • d0bfdb5f0de097e4460c13bc333755958fb30d4cb22e5f4475731ad1bdd579ec
  • d884b3178fc97d1077a13d47aadf63081559817f499163c2dc29f6828ee08cae
  • db1cbe1d85a112caf035fd5d4babfb59b2ca93411e864066e60a61ec8fe27368
  • 151[.]236.19.91
  • 78[.]47.218.106
  • 91[.]132.92.90
download

Tip: 29 related IOCs (3 IP, 0 domain, 0 URL, 0 email, 26 file hash) to this threat have been found.

FAQs

Crambus Campaign Targeting Middle Eastern Government

Over an eight-month period, attackers compromised multiple computers and servers belonging to a Middle Eastern government. The intruders stole files, captured passwords, and deployed hidden software to secretly monitor communications and execute commands on the network. They managed to compromise at least 12 core computers and likely deployed tools on dozens more.

The attack was carried out by a well-known Iranian espionage group known as Crambus, which is also tracked under the names OilRig and APT34. This group is highly experienced and frequently stages long-term intrusions for intelligence gathering and spying purposes. They have a deep history of targeting entities in the Middle East and surrounding regions.

The primary goal of the attack was cyber espionage and intelligence gathering. The attackers sought to maintain a quiet, long-term presence on the network to steal sensitive files, log keystrokes, and extract user credentials without being detected.

The attack was highly persistent and embedded deep within the targeted organization. The attackers maintained access for at least eight months, directly compromising a dozen servers and computers, including highly sensitive systems, while placing backdoors and keyloggers on many other machines.

Yes, this specific campaign was aimed directly at a government entity in the Middle East. The Crambus group traditionally targets governments and large organizations that are of geopolitical interest to Iran, often seeking sensitive state data or internal communications.

The attackers initially gained access and executed malicious scripts to establish a foothold. They relied heavily on legitimate remote access tools and specialized software hidden within the organization's internal email server to receive instructions secretly. They continuously mapped the network, stole passwords, and altered system settings to allow remote access to other computers.

Government entities handle highly sensitive political, diplomatic, and economic information. Because Crambus is a state-aligned espionage group, targeting regional governments provides valuable strategic intelligence that aligns with the geopolitical interests of their state sponsors.

Organizations should actively monitor their networks for unusual administrative tool usage or unexpected remote desktop connections. It is critical to regularly audit email server rules for suspicious filtering, hunt for unauthorized network scanning, and implement robust defenses against credential theft.

This specific incident was a highly targeted campaign against a single government entity. However, the Crambus group's ongoing activities show that they remain a continuous threat to various organizations, demonstrating that organizations in the region must remain on high alert.

About Affiliation
Crambus
Crambus is Symantec's designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. Symantec documented Crambus conducting a prolonged intrusion campaign against government organizations in a Middle Eastern country, maintaining persistent access for approximately eight months and deploying a range of novel backdoors including PowerExchange — a tool that uses Microsoft Exchange email for command and control. Crambus operations documented by Symantec in 2023 demonstrate the group's continued investment in new tooling and its ability to maintain extended access to government networks.
View Crambus's Insights