The APT34 group has resurfaced with a new attack . The Iran -linked group has been active since 2014 and primarily targets organizations in the financial, government, energy, and telecommunications sectors in the United States and Middle Eastern countries.
Researchers from FireEye have uncovered a new campaign espionagecarried out by the APT34 group (OilRig and HelixKitten, Greenbug). The hackers used LinkedIn for their campaign. Specifically, the group members presented themselves as researchers from Cambridge and asked victims to join network . Their goal, of course, is to distribute malware.
The researchers discovered the campaign in late June. According to them, there were three features that caught their attention:
- The appearance of hackers as Cambridge University professors-researchers to gain the trust of victims and convince them to open malicious documents
- Using LinkedIn to deliver malicious documents
- Addition of three new malware families to the hands of the AP34 group
One of the tools used by the group for the attacks is Pickpocket, which steals data and is exclusively linked to APT34 attacks.

The initial target was organizations in the energy, oil and gas sectors, as well as government agencies.
The hackers asked victims to open an infected file excel named ERFT-Details.xls. They sent the victim a message from LinkedIn, which purported to come from “Cambridge University Research Staff” and requested CVs for potential employment opportunities.
This technique, in which the hacker tries to gain the victim's trust, is known in many espionage campaigns.
The three new malware detected in this campaign have been named: TONEDEAF, VALUEVAULT , and LONGWATCH.
Tonedeaf is a backdoorthat communicates with a command-and-control server (C2) via HTTP GET and POST requests. It has the ability to collect information , upload and download files, and execute arbitrary commands.
ValueVault is a credential stealing tool and Longwatch is a keylogger.
“We suspect this won’t be the last time APT34 brings new tools,” the researchers said. The group is constantly using new methods to evade detection mechanisms, especially if the target is very important. For this reason, the company recommends that organizations be very careful and take care of the security of data .
