• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Microsoft Reveals Iran Hacking Campaign Targeting Mideast Experts

Jan 21, 2024, 13:33 GMT+0
Logo of Microsoft on its office building in Beijing, China, May 25, 2023
Logo of Microsoft on its office building in Beijing, China, May 25, 2023

Microsoft has revealed that "high-profile" experts specializing in Middle Eastern affairs are under attack from hackers believed to be linked to the Iranian government.

The entities under attack were located in Belgium, France, Gaza, Israel, the United Kingdom, and the United States.

The Microsoft Threat Intelligence team, in a recent blog post, outlined that since November, a faction of the hacking group Mint Sandstorm has utilized "customized phishing lures to socially engineer targets into downloading malicious files."

The report notes the application of new tools in observed incidents. According to Microsoft, the operators in the Mint Sandstorm subgroup exhibit highly skilled social engineering capabilities, lacking many typical hallmarks that users rely on to identify phishing emails. In some instances, the subgroup used compromised but legitimate accounts to disseminate phishing lures.

Microsoft's findings indicate a correlation between the recent campaign and the ongoing conflict in Gaza, with phishing lures referencing the Israel-Hamas war. The objective is to gather diverse internal perspectives on the conflict.

Mint Sandstorm, also known as APT35 or Charming Kitten, is associated with the Islamic Revolutionary Guard Corps (IRGC), an intelligence arm of Iran's military. The campaign primarily targets people with access to information crucial to Tehran's leadership.

Prior instances involve the group targeting journalists, researchers, professors, and others with resource-intensive social engineering campaigns. Some cases featured legitimate yet compromised email accounts belonging to the impersonated victims.

Initial emails in some instances lacked malicious content as hackers aimed to establish relationships with their targets before initiating espionage processes.


Most Viewed

US-Iran talks focused on phased deal to reopen Hormuz
1

US-Iran talks focused on phased deal to reopen Hormuz

2

Iran rules out nuclear concessions even if US accepts Hormuz proposal

3
INSIGHT

Pezeshkian straddles Iran’s divide at UN as US talks test balance

4
ANALYSIS

From Hormuz to Indian Ocean: Iran threatens to redraw the map of the war

5
VOICES FROM IRAN

'Bully at home, victim abroad': Iranians on Pezeshkian's UN speech

Banner
Banner

Spotlight

  • US and Iran want a deal, but neither wants to move first
    ANALYSIS

    US and Iran want a deal, but neither wants to move first

  • Rushdie returns to the fatwa that nearly cost him his life

    Rushdie returns to the fatwa that nearly cost him his life

  • Iranians report SIM cards blocked over political posts and likes
    VOICES FROM IRAN

    Iranians report SIM cards blocked over political posts and likes

  • Pezeshkian straddles Iran’s divide at UN as US talks test balance
    INSIGHT

    Pezeshkian straddles Iran’s divide at UN as US talks test balance

  • 'Bully at home, victim abroad': Iranians on Pezeshkian's UN speech
    VOICES FROM IRAN

    'Bully at home, victim abroad': Iranians on Pezeshkian's UN speech

  • War deepens Iran’s energy crunch ahead of winter
    ANALYSIS

    War deepens Iran’s energy crunch ahead of winter

Banner
Banner