• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Iran-Linked Hackers Target Nuclear Security Experts

Jul 8, 2023, 14:03 GMT+1

A state-sponsored Iranian hacker group recently employed a new infection chain to target a nuclear security expert at a US think tank.

Charming Kitten, also known as TA453, APT42, Mint Sandstorm, and Yellow Garuda earlier targeted high-value accounts in government, academia, NGOs, national security, and journalism.

As part of their recent operation, the IRGC-linked group used a benign email to begin a relationship with their target. Then they sent a follow-up email containing a malicious macro that directed the target to a Dropbox URL.

“Using a .rar and LNK file to deploy malware differs from TA453’s typical infection chain of using VBA macros or remote template injection. The LNK enclosed in the RAR used PowerShell to download additional stages from a cloud hosting provider,” a new analysis by Proofpoint says.

“The use of Google Scripts, Dropbox, and CleverApps demonstrates that TA453 continues to subscribe to a multi-cloud approach in its efforts to likely minimize disruptions from threat hunters. (...) Regardless of the infection method, TA453 continues to deploy modular backdoors in an effort to collect intelligence from highly targeted individuals,” Proofpoint said.

In April, Microsoft warned that hackers linked to Iran are targeting critical US infrastructure including transport, energy and ports. A report by Microsoft Threat Intelligence revealed the threat from the Iranian hackers, known as "Mint Sandstorm".

Initially engaged in reconnaissance, the subgroup eventually began attacking critical infrastructure organizations in the United States in 2022. In November 2021, the United States Justice Department indicted two Iranians, Mohammad Hosein Musa Kazemi and Sajjad Kashian, who were employed by Emennet Pasargad. During the 2020 presidential election, they allegedly conducted a cyber campaign "to intimidate and influence American voters".

Most Viewed

US carried out covert four-month Hormuz mine-clearing mission - FT
1

US carried out covert four-month Hormuz mine-clearing mission - FT

2

Iran oil workers protest pay conditions at offshore platforms, Assaluyeh

3
ANALYSIS

Iran’s new war strategy seeks to turn blockade into broader economic confrontation

4
ANALYSIS

Europe’s third-way ambitions on Iran give way to alignment with Washington

5
ANALYSIS

The gamble behind US attacks on Iran’s oil tankers

Banner
Banner
Banner

Spotlight

  • Iran’s gasoline price hike may add to revenues, but can it ease fuel shortage?
    ANALYSIS

    Iran’s gasoline price hike may add to revenues, but can it ease fuel shortage?

  • Iran deploys security forces as gasoline price rise takes effect
    VOICES FROM IRAN

    Iran deploys security forces as gasoline price rise takes effect

  • Iranian protester undergoes months of secret treatment to save wounded leg
    EXCLUSIVE

    Iranian protester undergoes months of secret treatment to save wounded leg

  • Iran’s new war strategy seeks to turn blockade into broader economic confrontation
    ANALYSIS

    Iran’s new war strategy seeks to turn blockade into broader economic confrontation

  • Europe’s third-way ambitions on Iran give way to alignment with Washington
    ANALYSIS

    Europe’s third-way ambitions on Iran give way to alignment with Washington

  • The gamble behind US attacks on Iran’s oil tankers
    ANALYSIS

    The gamble behind US attacks on Iran’s oil tankers