• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
All rights reserved for Volant Media UK Limited
volant media logo

Iran-Linked Hackers Target Nuclear Security Experts

Jul 8, 2023, 14:03 GMT+1

A state-sponsored Iranian hacker group recently employed a new infection chain to target a nuclear security expert at a US think tank.

Charming Kitten, also known as TA453, APT42, Mint Sandstorm, and Yellow Garuda earlier targeted high-value accounts in government, academia, NGOs, national security, and journalism.

As part of their recent operation, the IRGC-linked group used a benign email to begin a relationship with their target. Then they sent a follow-up email containing a malicious macro that directed the target to a Dropbox URL.

“Using a .rar and LNK file to deploy malware differs from TA453’s typical infection chain of using VBA macros or remote template injection. The LNK enclosed in the RAR used PowerShell to download additional stages from a cloud hosting provider,” a new analysis by Proofpoint says.

“The use of Google Scripts, Dropbox, and CleverApps demonstrates that TA453 continues to subscribe to a multi-cloud approach in its efforts to likely minimize disruptions from threat hunters. (...) Regardless of the infection method, TA453 continues to deploy modular backdoors in an effort to collect intelligence from highly targeted individuals,” Proofpoint said.

In April, Microsoft warned that hackers linked to Iran are targeting critical US infrastructure including transport, energy and ports. A report by Microsoft Threat Intelligence revealed the threat from the Iranian hackers, known as "Mint Sandstorm".

Initially engaged in reconnaissance, the subgroup eventually began attacking critical infrastructure organizations in the United States in 2022. In November 2021, the United States Justice Department indicted two Iranians, Mohammad Hosein Musa Kazemi and Sajjad Kashian, who were employed by Emennet Pasargad. During the 2020 presidential election, they allegedly conducted a cyber campaign "to intimidate and influence American voters".

Most Viewed

What does Trump mean by 'finish the job' in Iran?
1
ANALYSIS

What does Trump mean by 'finish the job' in Iran?

2

Netanyahu backs pressure-first strategy on Iran after Trump talks

3
INSIGHT

Did China quietly defuse Iran's oil weapon? Pro-Ghalibaf paper asks out loud

4

A teenage girl’s last act of defiance against Iran’s regime

5
INSIGHT

Iran government pushes talks line, but power lies elsewhere

Banner
Banner
Banner

Spotlight

  • Where steak is a dream
    VOICES FROM IRAN

    Where steak is a dream

  • 'Western trap': calls for restraint grow in Tehran after Ukraine attack
    INSIGHT

    'Western trap': calls for restraint grow in Tehran after Ukraine attack

  • State TV dispute exposes limits of oversight in Iran
    INSIGHT

    State TV dispute exposes limits of oversight in Iran

  • Iranian agents cut protester's royalist tattoos before killing him

    Iranian agents cut protester's royalist tattoos before killing him

  • Iran government pushes talks line, but power lies elsewhere
    INSIGHT

    Iran government pushes talks line, but power lies elsewhere

  • What does Trump mean by 'finish the job' in Iran?
    ANALYSIS

    What does Trump mean by 'finish the job' in Iran?