Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- Iran puts on show of force with war games ahead of Trump's second term - CBS News - January 9th, 2025 [January 9th, 2025]
- An American hostage during the Iran crisis remembers Jimmy Carter - BBC.com - January 9th, 2025 [January 9th, 2025]
- How Iran moves sanctioned oil around the world - Reuters - January 9th, 2025 [January 9th, 2025]
- Italian journalist Cecilia Sala released by Iran - The Washington Post - January 9th, 2025 [January 9th, 2025]
- Angry Trump roasts journalist when asked about Iran military strategy - The Independent - January 9th, 2025 [January 9th, 2025]
- UN says Iran executed over 900 people in 2024, including dozens of women - Reuters - January 9th, 2025 [January 9th, 2025]
- An Italian journalist is freed from detention in Iran and returns home - The Associated Press - January 9th, 2025 [January 9th, 2025]
- The Iran Opportunity: What America Needs to Do to Achieve a Breakthrough - Foreign Affairs Magazine - January 9th, 2025 [January 9th, 2025]
- France says conditions of citizens held in Iran akin to torture - Reuters - January 9th, 2025 [January 9th, 2025]
- Iran Pulls Most Forces From Syria, in Blow to Tehrans Regional Ambitions - The Wall Street Journal - January 9th, 2025 [January 9th, 2025]
- Shipping in the Crosshairs: What Trumps Return Could Mean for Iran and Maritime Trade - gCaptain - January 9th, 2025 [January 9th, 2025]
- OPEC oil output falls in December on UAE and Iran, survey finds - Reuters - January 9th, 2025 [January 9th, 2025]
- Yakuza boss pleads guilty to attempted nuclear trafficking to Iran - - January 9th, 2025 [January 9th, 2025]
- Iran to hold talks over its nuclear programme with European countries - Euronews - January 9th, 2025 [January 9th, 2025]
- Five years since the downing of Ukrainian airliner by Iran - Ukrainian World Congress - January 9th, 2025 [January 9th, 2025]
- Iran hostages reflect on a crisis that defined Jimmy Carters presidency: A fine man that did his best - The Guardian US - January 9th, 2025 [January 9th, 2025]
- Activists in Iran describe the threats and oppression they face for protesting - PBS NewsHour - January 9th, 2025 [January 9th, 2025]
- Iran diverts focus to West Bank after fall of Assad, Israel says - - January 9th, 2025 [January 9th, 2025]
- World News in Brief: Deadly China quake, Killings of Alawites in Syria, executions in Iran, CAR rights defenders, finance and food crises - UN News - January 9th, 2025 [January 9th, 2025]
- Turkey-backed Syria may be bigger threat than Iran, says Israeli government panel - Middle East Eye - January 9th, 2025 [January 9th, 2025]
- Tehrans proxies are on the back foot. An Iran-Russia defense pact could revive them. - Breaking Defense - January 9th, 2025 [January 9th, 2025]
- Italian PM says unaware of any Musk role in journalist's release from Iran - - January 9th, 2025 [January 9th, 2025]
- Japanese mafia leader caught in U.S. sting pleads guilty to conspiring to traffic nuclear materials to Iran - CBS News - January 9th, 2025 [January 9th, 2025]
- Report: Israel thinks Trump will back IDF strike on Iran nuke program or order US hit - The Times of Israel - January 9th, 2025 [January 9th, 2025]
- Iran tells France to review 'unconstructive' approach ahead of meeting - Reuters - January 9th, 2025 [January 9th, 2025]
- Welcoming election of Lebanese president, Iran says it wants to work with him - The Times of Israel - January 9th, 2025 [January 9th, 2025]
- Executions of women in Iran hit highest level in 17 years: report - JURIST - January 9th, 2025 [January 9th, 2025]
- Iran warns Italy that bilateral ties at risk if it bows to 'hostile' US demands over drone suspect - ABC News - January 6th, 2025 [January 6th, 2025]
- On GPS: How will Trump deal with Russia and Iran? - CNN - January 6th, 2025 [January 6th, 2025]
- Israels Red Sea Conundrum: Hit the Houthis or Iran - The Wall Street Journal - January 6th, 2025 [January 6th, 2025]
- Next nuclear talks between Iran and three European countries due on Jan 13 - Reuters - January 6th, 2025 [January 6th, 2025]
- A Last Chance for Iran: America Should Give Diplomacy a Final ShotWhile Preparing to Use Military Force - Foreign Affairs Magazine - January 6th, 2025 [January 6th, 2025]
- Iran's plot to assassinate dissident artist in Germany exposed | Iran International - - January 6th, 2025 [January 6th, 2025]
- Further Israeli strikes on Iran may lead to full-fledged war, FM warns - - January 6th, 2025 [January 6th, 2025]
- Report to Congress on Iran - USNI News - January 6th, 2025 [January 6th, 2025]
- Essay | The Untold Story of Jimmy Carters Hawkish Stand on Iran - The Wall Street Journal - January 6th, 2025 [January 6th, 2025]
- The Illusion of Influence: Iran's Fictional Tale of Soleimani and Putin - IranWire | - January 6th, 2025 [January 6th, 2025]
- Israel must confront Iran to weaken the Houthis - opinion - The Jerusalem Post - January 6th, 2025 [January 6th, 2025]
- Poverty in Iran: A Catalyst for Social Unrest and Regime Instability - Iran News Update - January 6th, 2025 [January 6th, 2025]
- What Will Trump Do About Iran? - by Jay Solomon - The FP - January 6th, 2025 [January 6th, 2025]
- U.S. imposes Russia, Iran sanctions over attempted election interference - The Washington Post - January 6th, 2025 [January 6th, 2025]
- Italy presses Iran for immediate release of journalist held in Tehran - The Guardian - January 6th, 2025 [January 6th, 2025]
- Israel confirms commandos raided Iran missile factory deep in Syria 4 months ago - The Times of Israel - January 6th, 2025 [January 6th, 2025]
- Iran to conduct extensive military drills in air, land, and sea - Tehran Times - January 6th, 2025 [January 6th, 2025]
- Iran in post-Assad Middle East: Will Khamenei's 2024 gamble haunt him in 2025? | Iran International - - January 6th, 2025 [January 6th, 2025]
- Former diplomat urges Iran to appoint envoy to mend ties with US - - January 6th, 2025 [January 6th, 2025]
- Iran providing Houthis with more arms after collapse of other armed allies - Telegraph - - January 6th, 2025 [January 6th, 2025]
- IDF on alert as Iran faces increasing pressures - JNS.org - January 6th, 2025 [January 6th, 2025]
- PM: Iran dumbfounded by Israeli strikes, saw investment in proxies go down the tubes - The Times of Israel - December 22nd, 2024 [December 22nd, 2024]
- Iran could build nuclear weapon, Trump told by White House - The Telegraph - December 22nd, 2024 [December 22nd, 2024]
- The year ahead in the Middle East: A weakened Iran has big implications for China - The Conversation - December 22nd, 2024 [December 22nd, 2024]
- The Iran-led axis of resistance in the aftermath of Syrias upheaval - Al Jazeera English - December 22nd, 2024 [December 22nd, 2024]
- PM vows escalated fight against Houthis; officials said urging direct attack on Iran - The Times of Israel - December 22nd, 2024 [December 22nd, 2024]
- Analysis: The Islamic State and Iran remain determined to attack the US - Long War Journal - December 22nd, 2024 [December 22nd, 2024]
- Khamenei says Iran does not have or need proxy forces in Middle East - The Times of Israel - December 22nd, 2024 [December 22nd, 2024]
- Iran plagued by energy crisis partially caused by strikes attributed to Israel - The Times of Israel - December 22nd, 2024 [December 22nd, 2024]
- US imposes sanctions on Iran and Houthi-related targets - Reuters - December 22nd, 2024 [December 22nd, 2024]
- Christmas in Tehran During the 1979 Iran Hostage Crisis - The New Yorker - December 22nd, 2024 [December 22nd, 2024]
- Women Being Sent to the Gallows in Alarming Numbers in Iran - Center for Human Rights in Iran - December 22nd, 2024 [December 22nd, 2024]
- Trump Reportedly Offers To Hold High-level Nuclear Talks With Iran - i24NEWS - December 22nd, 2024 [December 22nd, 2024]
- Iran pauses the process to implement a new, stricter headscarf law for women, official says - The Associated Press - December 22nd, 2024 [December 22nd, 2024]
- Documents captured from Hamas reveal Iran's complex weapons smuggling network - The Jerusalem Post - December 22nd, 2024 [December 22nd, 2024]
- UN pushes for Iran nuclear deal talks, says 'time of the essence' - Reuters.com - December 22nd, 2024 [December 22nd, 2024]
- Netanyahu: 'Just as we acted forcefully against Iran's axis of evil, we will act against Houthis' - The Jerusalem Post - December 22nd, 2024 [December 22nd, 2024]
- The Middle East Is in Chaos. Iran Is Focused on the Veil. - Foreign Policy - December 22nd, 2024 [December 22nd, 2024]
- Iran expands weaponization capabilities critical for employing nuclear bomb - Fox News - December 22nd, 2024 [December 22nd, 2024]
- Iran: Only Three Days of Electricity and Gasoline Per Week - Iran Focus - December 22nd, 2024 [December 22nd, 2024]
- Iran celebrates 3rd anniversary of Yalda Nights UNESCO designation - Tehran Times - December 22nd, 2024 [December 22nd, 2024]
- Its proxies pummeled, Iran is suddenly more vulnerable than ever. Will it go nuclear? - The Times of Israel - December 22nd, 2024 [December 22nd, 2024]
- FIFA hails all-women crowd of 45K at game in Iran - ESPN - December 22nd, 2024 [December 22nd, 2024]
- Two charged in connection with Iran-backed drone strike that killed 3 US troops in the Middle East - The Associated Press - December 22nd, 2024 [December 22nd, 2024]
- Syrians have every right to hate us Iranians | Iran International - - December 22nd, 2024 [December 22nd, 2024]
- UN monitor says reviving Iran deal now irrelevant, since Tehran on cusp of nuke - The Times of Israel - December 22nd, 2024 [December 22nd, 2024]
- Syria has been liberated from Russia and Iran but outsiders still threaten its new freedom - The Guardian - December 22nd, 2024 [December 22nd, 2024]
- Western sabotage intended to create chaos in Iran - Tehran Times - December 22nd, 2024 [December 22nd, 2024]
- Iran throws its support behind Assad as rebels expand their shock offensive in Syria - NBC News - December 2nd, 2024 [December 2nd, 2024]
- Iran says insecurity in Syria will spread beyond borders - - December 2nd, 2024 [December 2nd, 2024]
- Iran to begin enriching uranium with thousands of advanced centrifuges, UN watchdog says - The Associated Press - December 2nd, 2024 [December 2nd, 2024]
- Rebels in Syria take advantage of Israels successes against a weakened Iran axis - The Times of Israel - December 2nd, 2024 [December 2nd, 2024]
- Avoiding the next front: Iraqs fight to stay out of the Israel-Iran conflict - European Council on Foreign Relations - December 2nd, 2024 [December 2nd, 2024]