HomeSecurityIranian hackers behind highly targeted espionage campaign

Iranian hackers behind highly targeted espionage campaign

Iranian hackers appear to be behind a new espionage campaign against a Jordanian diplomat that recently came to the attention of security researchers.

See also: "Blood is on your hands": Hackers take over Russian television

Iranian hackers

The attack, attributed to the Iranian hacking group APT34 or Oilrig, involved advanced anti-detection and anti-analysis techniques and had certain characteristics that suggest long-term and careful preparation.

Security researchers at Fortinet collected evidence and artifacts from the May 2022 attack and compiled a technical report to highlight APT34's latest techniques and methods

The Iranian hackers used a spear-phishing email, pretending to be a colleague of the diplomat in the government, with the email address forged accordingly.

The email contained a malicious Excel, which contained VBA macro code that runs to create three files, a malicious executable, a configuration file, and a signed and clean DLL. The macro also creates persistence for the malicious executable (update.exe) by adding a scheduled task that repeats every four hours.

See also: French hospitals targeted by hackers – Data stolen

Another unusual finding concerns two anti-analysis mechanisms implemented in the macro: toggling sheet visibility in the spreadsheet and a check for the presence of a mouse, which may not be present in malware analysis sandbox services

espionage campaign

The malicious executable is a .NET that checks program states and goes dormant for eight hours after launch. Analysts believe the Iranian hackers likely set this delay on the assumption that the diplomat would open the email in the morning and leave after eight hours, so that the computer would remain unattended.

When active, the malware communicates with C2 subdomains using a Domain Generation Algorithm (DGA) tool. DGA is a widely used technique that makes malware operations more resistant to domain takedowns and block registration.

It then creates a DNS tunnel to communicate with the provided IP address. This is a rare technique that helps threat actors encrypt the data exchanged as part of this communication, making it difficult for network monitors to catch anything suspicious.

See also: Hackers target Ukrainian government agencies with Zimbra exploits and IcedID malware

The C2 then sends twenty-two different backdoor to the malware, which are executed via PowerShell or the Windows CMD interpreter. Finally, the stolen data is extracted via DNS, with the data embedded in the request, making it appear as standard in network logs.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS