A new malware called ForeLord has been detected by security. It has been found that Iranian hackers are using it to attack government organizations via MS Excel files.
The Iranian hacking group , known as COBALT ULSTER or MuddyWater, is behind this attack and it is believed to be retaliatory actions against the US for the killing of Iranian General Soleimani on January 2, 2020 .
This group, as has been observed since last year, has introduced a new set of exploits into its arsenal as well as tactics, techniques, and procedures, so that it can target government entities and telecommunications sectors.
Researchers also identified a series of malicious campaigns that took place from mid-2019 to mid-January 2020 and targeted government organizations in Turkey, Jordan, and Iraq.

What is ForeLord?
It is a trojan , often distributed via a malicious Excel document containing a macro with a secret mechanism that creates persistence.
In the initial phase of the attack, malicious actors send emails that deliver a ZIP file, which contains malicious Excel.
This malicious Excel file is used as a macro that helps install the ForeLord RAT, while at the same time the malicious document uses cmd.exe to execute a batch script to add a key to the registry, which will allow it to remain on the system even when the victim reboots.
Once malicious actors gain access, in this case Iranian hackers, they download various tools, such as PasswordDumper.exe, PASS32.dll, Mimikatz, and others, to collect credentials, verify credentials present on the network, and create a reverse SSL tunnel to provide an additional access channel to the network.
Specifically, one of the open source penetration testing tools, known as CredNinja.ps1, is used in this attack to collect credentials.
Finally, they use another tool called Secure Socket Funneling, a network tool and set of tools to forward stolen data from multiple sockets, through a single TLS tunnel to a remote computer.
