Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- Iran says German-Iranian died before execution was reported - BBC.com - November 5th, 2024 [November 5th, 2024]
- Iran is now dangerously vulnerable to the consequences of another attack on Israel - Business Insider - November 5th, 2024 [November 5th, 2024]
- Federal agencies say Russia and Iran are ramping up influence campaigns targeting US voters - The Associated Press - November 5th, 2024 [November 5th, 2024]
- Three sentenced to death in Iran over killing of top nuclear scientist - Al Jazeera English - November 5th, 2024 [November 5th, 2024]
- Russia launches Soyuz rocket with dozens of satellites, including two from Iran - Reuters - November 5th, 2024 [November 5th, 2024]
- Full-scale war in Middle East involving Israel and Iran likely, say most Europeans in poll - The Guardian - November 5th, 2024 [November 5th, 2024]
- Iran executes a Jewish citizen convicted of murder following a dispute over money - ABC News - November 5th, 2024 [November 5th, 2024]
- US says Iranian-American held in Iran as tensions high following Israeli attack on country - The Associated Press - November 5th, 2024 [November 5th, 2024]
- An Iranian-American journalist is believed to be held by Iran as tensions remain high after an Israeli attack, US says - ABC News - November 5th, 2024 [November 5th, 2024]
- Iran Issues Fresh Threats Against Israel, U.S. - Foundation for Defense of Democracies - November 5th, 2024 [November 5th, 2024]
- Iran arrests female university student who stripped to her underwear in protest over dress code enforcement - CBS News - November 5th, 2024 [November 5th, 2024]
- Oil prices settle up slightly on Iran worries, but prices down for week - Reuters - November 5th, 2024 [November 5th, 2024]
- Two members of Iran's Revolutionary Guards killed in helicopter crash - FRANCE 24 English - November 5th, 2024 [November 5th, 2024]
- Iran wants to hold region hostage with retaliation op - analysis - The Jerusalem Post - November 5th, 2024 [November 5th, 2024]
- Iran slams destabilizing presence as US sends B-52 bombers to region - The Times of Israel - November 5th, 2024 [November 5th, 2024]
- Woman strips off clothes at Iran university in apparent protest, reports say - Reuters - November 5th, 2024 [November 5th, 2024]
- Iran says two French detainees held in good conditions - Reuters - November 5th, 2024 [November 5th, 2024]
- Reformist clerics imply Iran should back two-state solution for Israel and Palestine - The Guardian - November 5th, 2024 [November 5th, 2024]
- Iran to use bigger warheads in attack on Israel - JNS.org - November 5th, 2024 [November 5th, 2024]
- Will Iran Withdraw from the Nuclear Non-Proliferation Treaty? - War On The Rocks - November 5th, 2024 [November 5th, 2024]
- From Iran to Turkey, how the Middle East is bracing for US elections - Al-Monitor - November 5th, 2024 [November 5th, 2024]
- Iran Rejects Nuclear Weapons but Will 'Defend Itself by All Means' - Newsweek - November 5th, 2024 [November 5th, 2024]
- Iran vows strong and complex attack against Israel in retaliation for strikes - New York Post - November 5th, 2024 [November 5th, 2024]
- US said to warn Iran it wont be able to restrain Israel if Tehran attacks again - The Times of Israel - November 5th, 2024 [November 5th, 2024]
- The Houthis couldn't have built their most dangerous weapons without help from Iran and others, UN experts find - Business Insider - November 5th, 2024 [November 5th, 2024]
- Iran detains woman who stripped to her underwear at university in apparent protest - ABC News - November 4th, 2024 [November 4th, 2024]
- Iran executes Jewish Iranian man after settlement aimed at saving him was rejected - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Israel says it conducted a ground raid in Syria and seized a Syrian citizen connected to Iran - PBS NewsHour - November 4th, 2024 [November 4th, 2024]
- Iran said planning to use more powerful weapons in next attack on Israel - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- The Longer Iran Waits to Attack Israel, the More Risks It Takes - Haaretz - November 4th, 2024 [November 4th, 2024]
- Iran's enemies will receive crushing response - Khamenei - BBC.com - November 4th, 2024 [November 4th, 2024]
- Iran fears Trump win would bring Israeli strikes on nuclear sites, Western sanctions - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Israel says it carried out ground raid into Syria, seizing a Syrian citizen connected to Iran - The Associated Press - November 4th, 2024 [November 4th, 2024]
- Israel Iran war Live Updates: IDF says it eliminated Hezbollah commander Abu Ali Rida - The Times of India - November 4th, 2024 [November 4th, 2024]
- Iran plans strong and complex attack on Israel as Khamenei vows 'harsh retaliation' | What we know so far | Today News - Mint - November 4th, 2024 [November 4th, 2024]
- 'Orders to come from Iran': Iraqi militias pose growing risk to Israel - expert - The Jerusalem Post - November 4th, 2024 [November 4th, 2024]
- Iraq trying to reel in Iran-backed groups to prevent confrontation with Israel - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Iran warns of 'crushing response' following Israeli airstrikes as Pentagon announces plans to bolster US presence in the Middle East - Business... - November 4th, 2024 [November 4th, 2024]
- Khamenei aide warns Iran may review nuclear doctrine if facing existential threat - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Iran Is Freaked: The Air Force Is Sending B-52 Bombers Much Closer - The National Interest Online - November 4th, 2024 [November 4th, 2024]
- Israel at War Day 394 | Report: Iran's Army Will Participate in 'Strong and Complex' Attack on Israel - Haaretz - November 4th, 2024 [November 4th, 2024]
- Iran says airspace remains open - The Jerusalem Post - November 4th, 2024 [November 4th, 2024]
- UN experts say Houthis exploited Gaza war to boost regional status, aided by Iran - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Netanyahu tells U.S. that Israel will strike Iranian military, not nuclear or oil, targets, officials say - The Washington Post - October 16th, 2024 [October 16th, 2024]
- Opinion | Its Time for America to Get Real With Iran and Israel - The New York Times - October 16th, 2024 [October 16th, 2024]
- Iran says it will respond decisively if Israel attacks, asks UN to intervene - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- US warns Iran to stop plotting against Trump, says US official - Reuters - October 16th, 2024 [October 16th, 2024]
- Iran working to control oil spill off Kharg Island, says IRNA - Reuters - October 16th, 2024 [October 16th, 2024]
- Israel said to decide on targets it could strike in Iran: Now a matter of time - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Israel will respond to Iran based on national interest - Netanyahu - BBC.com - October 16th, 2024 [October 16th, 2024]
- Israel Tells U.S. It Will Limit Its Expected Strike on Iran to Military Targets, Officials Say - The New York Times - October 16th, 2024 [October 16th, 2024]
- Israeli arrested for plot to kill local scientist in exchange for $100K from Iran - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Israel is ready to strike Iran with attack expected before US election: report - New York Post - October 16th, 2024 [October 16th, 2024]
- Iran Shouldnt Expect Russia to Come Riding to Its Rescue - Carnegie Endowment for International Peace - October 16th, 2024 [October 16th, 2024]
- Jordan tells Iran it will not allow anyone to violate its airspace - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Iran has a big surprise and is waiting for zero hour, warns senior IRGC officer - Middle East Monitor - October 16th, 2024 [October 16th, 2024]
- Iran cyber attacks against Israel surged after Gaza war started, Microsoft reports - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Sudans civil war fueled by secret arms shipments from UAE and Iran - The Washington Post - October 16th, 2024 [October 16th, 2024]
- Israel launches new strikes in Beirut despite U.S. warning over scale of attacks on Iran-backed Hezbollah - CBS News - October 16th, 2024 [October 16th, 2024]
- Any retaliation against Iran will be based on national interest, says Israel - The Guardian - October 16th, 2024 [October 16th, 2024]
- Would Iran Close the Strait of Hormuz in a Conflict? - The Maritime Executive - October 16th, 2024 [October 16th, 2024]
- Why The Exiled Crown Prince of Iran Is Urging Israel to 'Take Down' The Tyrannical Regime - CBN.com - October 16th, 2024 [October 16th, 2024]
- Israel has these four options for attacking Iran - The Economist - October 16th, 2024 [October 16th, 2024]
- Iran has a hit list of former Trump aides. The U.S. is scrambling to protect them. - POLITICO - October 14th, 2024 [October 14th, 2024]
- Biden warned Iran that killing Trump would be an act of war: report - Fox News - October 14th, 2024 [October 14th, 2024]
- Harris to Jewish voters: All options on the table to stop Iran from going nuclear - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- Secret Documents Show Hamas Tried to Persuade Iran to Join Its Oct. 7 Attack - The New York Times - October 14th, 2024 [October 14th, 2024]
- Video: Iran warns US that it will retaliate against any future Israel strike - CNN - October 14th, 2024 [October 14th, 2024]
- Iran says it halted indirect talks with US in Oman as it waits for Israeli retaliation - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- EU includes Iran Air in sanctions over missile transfer to Russia - Reuters - October 14th, 2024 [October 14th, 2024]
- US will send a missile defense system and troops to run it to Israel to aid defense against Iran - The Associated Press - October 14th, 2024 [October 14th, 2024]
- Two Israelis arrested for acts of sabotage, plotting assassination for Iran - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- As Israel plots to strike Iran, its choices range from symbolic to severe - The Associated Press - October 14th, 2024 [October 14th, 2024]
- Uncertainty looms over Israels expected Iran strike; rescuers dig through debris in central Beirut - The Washington Post - October 14th, 2024 [October 14th, 2024]
- Iran Issues New Warning: 'We Have No Red Line' - Newsweek - October 14th, 2024 [October 14th, 2024]
- Iran's attacks on Israel suggest ballistic missiles are an overhyped threat - Business Insider - October 14th, 2024 [October 14th, 2024]
- A US missile-defense system, hailed as the world's best, is headed to Israel to counter Iran - Business Insider - October 14th, 2024 [October 14th, 2024]
- 'No red lines' in defending Iran and its interests, foreign minister says - FRANCE 24 English - October 14th, 2024 [October 14th, 2024]
- Iran bans pagers, walkie talkies on planes after blasts targeting Hezbollah members - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- Putin hails very close links with Iran at landmark first meeting with president, as Middle East tensions soar - CNN - October 14th, 2024 [October 14th, 2024]