Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- Khamenei aide: Iran will have no choice but to acquire nukes if attacked - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- How dangerous are the tensions between the US and Iran? - Al Jazeera - April 1st, 2025 [April 1st, 2025]
- Russia condemns Trumps threat to bomb Iran over nuclear standoff - Anadolu Ajans - April 1st, 2025 [April 1st, 2025]
- Iran threatens preemptive strike on base housing US bombers, report says - Ynetnews - April 1st, 2025 [April 1st, 2025]
- Exclusive: Iran has readied missiles for potential response amid Trump's escalating threats - Tehran Times - April 1st, 2025 [April 1st, 2025]
- Iran's Khamenei vows retaliation if Trump threat enacted - DW - April 1st, 2025 [April 1st, 2025]
- Iran has rejected direct negotiations with the US in response to Trumps letter - AP News - April 1st, 2025 [April 1st, 2025]
- US sanctions entities in Iran, China, UAE, for assisting Tehran with weapons procurement - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- Khamenei adviser says Iran will have no choice but to get nuclear weapon if attacked - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- A Ticking Bomb: Israeli Eliminates Iran-Linked Terrorist in Beirut - Foundation for Defense of Democracies - April 1st, 2025 [April 1st, 2025]
- 'Will have no choice': Iran warns it may have to acquire nuclear weapons if attacked - Times of India - April 1st, 2025 [April 1st, 2025]
- Trump threatens there will be bombing if Iran fails to make deal on nukes - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- Suspected missile cargo ship arrives in Iran from China as nuclear tensions escalate - Newsweek - April 1st, 2025 [April 1st, 2025]
- Trump threatens to bomb Iran if nuclear deal cant be reached - Politico - April 1st, 2025 [April 1st, 2025]
- Trump warns Iran could see 'bombing the likes of which they have never seen' - www.israelhayom.com - April 1st, 2025 [April 1st, 2025]
- Iran rejects direct nuclear talks with Trump, open to indirect negotiations - Al Jazeera - April 1st, 2025 [April 1st, 2025]
- Iran's Supreme Leader Responds to Trump Bombing Threat - Newsweek - April 1st, 2025 [April 1st, 2025]
- Is Iran on a collision course with the west? - Financial Times - April 1st, 2025 [April 1st, 2025]
- Trump says 'there will be bombing' if Iran does not make nuclear deal - USA Today - April 1st, 2025 [April 1st, 2025]
- Mapped: These are the nuclear sites in Iran the US and Israel could hit if talks fail - Ynetnews - April 1st, 2025 [April 1st, 2025]
- Trump warns Iran of bombing like never seen before if no deal reached - - April 1st, 2025 [April 1st, 2025]
- IDF reorganizes units responsible for Iran planning - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- Trump threatens to bomb Iran unless deal on nuclear program is reached - The Independent - April 1st, 2025 [April 1st, 2025]
- Trump's threat to Iran that 'there will be bombing' comes amid new B-2 stealth bomber moves - Business Insider - April 1st, 2025 [April 1st, 2025]
- Israel and the United States are Ready to Strike Iran - The National Interest - April 1st, 2025 [April 1st, 2025]
- Two Carriers in the Middle East: Implications for the Houthis, Iran, and U.S. Force Readiness - The Washington Institute - April 1st, 2025 [April 1st, 2025]
- Iran Is Freaked: Trump and Israel Could Launch a Joint Strike - 19FortyFive - April 1st, 2025 [April 1st, 2025]
- Trump's threat to Iran that 'there will be bombing' comes amid new B-2 stealth bomber moves - MSN - April 1st, 2025 [April 1st, 2025]
- Iran rejects offer of direct US negotiations over rapidly growing nuclear program - New York Post - April 1st, 2025 [April 1st, 2025]
- Trump's threat to Iran that 'there will be bombing' comes amid new B-2 stealth bomber moves - Yahoo - April 1st, 2025 [April 1st, 2025]
- Trumps Middle East strategy is all about striking an Iran deal. Gaza could get in the way. - Atlantic Council - March 25th, 2025 [March 25th, 2025]
- US Threatens 'All Options on the Table' for Iran - Newsweek - March 25th, 2025 [March 25th, 2025]
- Trump's offer of talks with Iran aims to avoid military action, US envoy says - Reuters - March 25th, 2025 [March 25th, 2025]
- Trumps Advisers Are Divided on Iran. Which Way Is the President Leaning? - The FP - March 25th, 2025 [March 25th, 2025]
- Iranians discuss Trump envoys interest in visiting Tehran | Iran International - - March 25th, 2025 [March 25th, 2025]
- Iran's top medical body warns of skilled staff exodus - - March 25th, 2025 [March 25th, 2025]
- Iran says it will consider 'opportunities' as well as threats in Trump letter - Reuters - March 25th, 2025 [March 25th, 2025]
- Khamenei says Houthis act independently, warns against US strikes on Iran - The Times of Israel - March 25th, 2025 [March 25th, 2025]
- Iran condemns US threats to use force and vows to defend its sovereignty - The Times of Israel - March 25th, 2025 [March 25th, 2025]
- Iran's Khamenei says US threats 'will get them nowhere' - FRANCE 24 English - March 25th, 2025 [March 25th, 2025]
- Iran's Supreme Leader Threatens US with "Severe Blow" - Newsweek - March 25th, 2025 [March 25th, 2025]
- Iran's supreme leader says Trump administration threats over nuclear program "will get them nowhere" - CBS News - March 25th, 2025 [March 25th, 2025]
- Iran open to indirect talks with US, rejects direct negotiations under pressure - Arutz Sheva - March 25th, 2025 [March 25th, 2025]
- How a war with Iran (for Israel) could crash the US economy - The Cradle - March 25th, 2025 [March 25th, 2025]
- Iran has 'got to address that fact that the world they knew is over': State Department spox - Fox Business - March 25th, 2025 [March 25th, 2025]
- No one can even think of attack on Iran, FM asserts - Tehran Times - March 25th, 2025 [March 25th, 2025]
- The Islamic Republic of Iran only understands one language: 'Language of pressure,' journalist say - Fox Business - March 25th, 2025 [March 25th, 2025]
- French citizen Olivier Grondeau is freed after over 880 days in a prison in Iran - The Associated Press - March 25th, 2025 [March 25th, 2025]
- Iran's leader warns US could receive 'severe slaps' following Trump's threats to Houthis - Fox News - March 25th, 2025 [March 25th, 2025]
- US and Israel Have Laid the Groundwork for War With Iran. Will Trump Set It Off? - Truthout - March 25th, 2025 [March 25th, 2025]
- Senior Saudi Journalist Tariq Al-Homayed: Iran Must Stop Its Expansion Project And Pursuit Of Nuclear Weapons, End The Futile Wars Waged By Its... - March 25th, 2025 [March 25th, 2025]
- Chinas five-point proposition on the Iran nuclear issue - Tehran Times - March 25th, 2025 [March 25th, 2025]
- Iran says its open to indirect negotiations with US over nuclear program - The Times of Israel - March 25th, 2025 [March 25th, 2025]
- Report: Trump letter to Iran set 2-month deadline to reach nuclear deal - The Times of Israel - March 25th, 2025 [March 25th, 2025]
- Why wont Britain take the threat of Iran seriously? - The Times - March 25th, 2025 [March 25th, 2025]
- Trump drops two-month deadline on nuclear deal with Iran - The Jerusalem Post - March 25th, 2025 [March 25th, 2025]
- Trump's tactics with Canada are pushing the prize of an Iran nuclear deal further away - The National - March 25th, 2025 [March 25th, 2025]
- What to do with Iran and its Houthi proxies: Attack! - The Hill - March 25th, 2025 [March 25th, 2025]
- US envoy Witkoff says Trump wants to build trust with Iran to avoid armed conflict - The National - March 25th, 2025 [March 25th, 2025]
- Twilight of the Islamic Republic: The rocky road to regime change in Iran has begun - opinion - The Jerusalem Post - March 25th, 2025 [March 25th, 2025]
- Iran leader rejects nuclear talks with US as Trump letter arrives - BBC.com - March 13th, 2025 [March 13th, 2025]
- Iraq says seeking alternatives to Iran gas - Yahoo - March 13th, 2025 [March 13th, 2025]
- What to know about tensions between Iran and the US as Trump sends a letter to its supreme leader - The Associated Press - March 13th, 2025 [March 13th, 2025]
- 'This threat is unwise': Iran's Khamenei cautions Trump against potential military action - FRANCE 24 English - March 13th, 2025 [March 13th, 2025]
- Iran Could Lose Iraq: The Axis of Resistance Is Primed to Take Another Hit - Foreign Affairs Magazine - March 13th, 2025 [March 13th, 2025]
- Attacking Iran's Nuclear Program: The Complex Calculus of Preventive Action - The Washington Institute - March 13th, 2025 [March 13th, 2025]
- An Emirati diplomat identified as having a letter from Trump meets with Iran's foreign minister - The Associated Press - March 13th, 2025 [March 13th, 2025]
- China, Russia, Iran to hold nuclear talks in Beijing on Friday - Reuters - March 13th, 2025 [March 13th, 2025]
- Iran's President to Trump: I will not negotiate, 'do whatever the hell you want' - Reuters - March 13th, 2025 [March 13th, 2025]
- Iran's president refuses talks, tells Trump 'do whatever the hell you want' - Middle East Eye - March 13th, 2025 [March 13th, 2025]
- UAE official delivers to Iran letter from Trump urging nuclear talks - The Times of Israel - March 13th, 2025 [March 13th, 2025]
- What to know about tensions between Iran and the US as Trump sends a letter to its supreme leader - Greenville Daily Reflector - March 13th, 2025 [March 13th, 2025]
- Iraq says seeking alternatives to Iran gas - Wyoming News Now - March 13th, 2025 [March 13th, 2025]
- What to know about tensions between Iran and the US as Trump sends a letter to its supreme leader - Northeast Mississippi Daily Journal - March 13th, 2025 [March 13th, 2025]
- Beach turns bright red in Iran: 5 things about bizarre 'blood rain' phenomenon that stunned internet - Hindustan Times - March 13th, 2025 [March 13th, 2025]
- What to know about tensions between Iran and the US as Trump sends a letter to its supreme leader - Cecil Daily - March 13th, 2025 [March 13th, 2025]
- Iran Tells Trump: "Do Whatever The Hell You Want." - Newsweek - March 13th, 2025 [March 13th, 2025]
- Striking the head: Israel's Iran strategy | Daily Sabah - Daily Sabah - March 13th, 2025 [March 13th, 2025]
- Iran's supreme leader rejects talks with the U.S., says it's "not aimed at solving problems" - CBS News - March 13th, 2025 [March 13th, 2025]
- Iran steps up crackdown on female singers with social media bans | Iran International - - March 13th, 2025 [March 13th, 2025]