• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
All rights reserved for Volant Media UK Limited
volant media logo

Microsoft Reveals Iran Hacking Campaign Targeting Mideast Experts

Jan 21, 2024, 13:33 GMT+0
Logo of Microsoft on its office building in Beijing, China, May 25, 2023
Logo of Microsoft on its office building in Beijing, China, May 25, 2023

Microsoft has revealed that "high-profile" experts specializing in Middle Eastern affairs are under attack from hackers believed to be linked to the Iranian government.

The entities under attack were located in Belgium, France, Gaza, Israel, the United Kingdom, and the United States.

The Microsoft Threat Intelligence team, in a recent blog post, outlined that since November, a faction of the hacking group Mint Sandstorm has utilized "customized phishing lures to socially engineer targets into downloading malicious files."

The report notes the application of new tools in observed incidents. According to Microsoft, the operators in the Mint Sandstorm subgroup exhibit highly skilled social engineering capabilities, lacking many typical hallmarks that users rely on to identify phishing emails. In some instances, the subgroup used compromised but legitimate accounts to disseminate phishing lures.

Microsoft's findings indicate a correlation between the recent campaign and the ongoing conflict in Gaza, with phishing lures referencing the Israel-Hamas war. The objective is to gather diverse internal perspectives on the conflict.

Mint Sandstorm, also known as APT35 or Charming Kitten, is associated with the Islamic Revolutionary Guard Corps (IRGC), an intelligence arm of Iran's military. The campaign primarily targets people with access to information crucial to Tehran's leadership.

Prior instances involve the group targeting journalists, researchers, professors, and others with resource-intensive social engineering campaigns. Some cases featured legitimate yet compromised email accounts belonging to the impersonated victims.

Initial emails in some instances lacked malicious content as hackers aimed to establish relationships with their targets before initiating espionage processes.


Most Viewed

Khamenei fills six top military posts as key intelligence gaps persist
1

Khamenei fills six top military posts as key intelligence gaps persist

2
INSIGHT

From Karbala-4 to AMIA: Mohsen Rezaei returns to Iran’s security helm

3

Mojtaba Khamenei orders integration of Iran’s top military command bodies

4

Iran parliament advances Hormuz bill targeting US, Israeli transit

5
INSIGHT

Iran plays down Mecca Pact as regional security order shifts

Banner
Banner
Banner

Spotlight

  • Iran hardliners tout offensive posture as Khamenei reshapes military command
    INSIGHT

    Iran hardliners tout offensive posture as Khamenei reshapes military command

  • The Kinglet’s rookie mistake: how an Iranian hacker was caught at US request
    SPECIAL REPORT

    The Kinglet’s rookie mistake: how an Iranian hacker was caught at US request

  • Rising costs leave Iranians 'nothing' for a coffee
    VOICES FROM IRAN

    Rising costs leave Iranians 'nothing' for a coffee

  • Two years on, Pezeshkian’s presidency is a tale of survival
    INSIGHT

    Two years on, Pezeshkian’s presidency is a tale of survival

  • From Karbala-4 to AMIA: Mohsen Rezaei returns to Iran’s security helm
    INSIGHT

    From Karbala-4 to AMIA: Mohsen Rezaei returns to Iran’s security helm

  • The strange power of Iran’s absent supreme leader
    ANALYSIS

    The strange power of Iran’s absent supreme leader