HomeSecuritySpear-phishing: Iranian hackers target US government employees

Spear-phishing: Iranian hackers target US government employees

spear phishingAccording to a study by security firm Integer Labs, an Iranian hacking group is carrying out spear-phishing attacks targeting government employees U.S.. Researchers have linked the attacks to a hacking group known as APT34 or OilRig.

APT34 is affiliated with and funded by the Iranian government and has been active for six years. It is primarily involved in espionage.

The goal of its new attacks is to install malware . on US government systems

According to the research, hackers have launched a very “smart” and well-organized spear-phishing campaign.

Hackers are sending spear-phishing emails that purport to come from Westat, a company that conducts studies on government agencies. It is a well-known company and has conducted surveys for more than 80 federal agencies over the past 16 years. Typically, employees are asked to answer questions about working conditions, management, and job satisfaction.

Intezer says that APT34 sends fake emails that closely resemble Westat's and distributes "surveys" in an Excel.

New improved malware

These documents contain malicious code that is executed if the victim enables macros in Excel. According to the researchers, the malicious code downloads and installs two malware, TONEDEAF and VALUEVAULT.

One is a backdoor, while the other a password stealer .

They have been used again by the APT34 group, in a spear-phishing campaign that took place last July.

However, researchers claim that these are new, improved versions of the malware, modified to serve the goals of this specific campaign.

For example, VALUEVAULT now includes a feature to steal passwords from the Chrome browser, while it previously exploited Windows Vault. The change was likely made because US government agencies are known to use Chrome.

Intezer has named the new versions of the malware TONEDEAF 2.0 and VALUEVAULT 2.0.

Apparently, the hackers tried to improve their hacking tools in an attempt to avoid detection after the attack was discovered.

We still don't know when this APT34 spear-phishing campaign, presented as a Westat study, began.

Spear-phishing: Iranian hackers target US government employees

The campaign continues

“What we do know is that the malware ’s command and control domain was created 4 months ago and a certificate was issued for the website a month ago ,” said Paul Litvak, a malware analyst at Intezer Labs.

Litvak believes the campaign is still ongoing and warns that in addition to government employees, other commercial entities participating in Westat studies may also be at risk.

Intezer said it informed Westat about the incident yesterday.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS