The Iranian hacking group Charming Kitten is actively targeting multiple victims in the US, Europe, the Middle East, and India with a new malware called BellaCiao, adding it to its ever-expanding list of custom tools.

BellaCiao, discovered by Bitdefender Labs, is a “personalized dropper” capable of delivering other malware payloads to a machine based on commands it receives from an attacker-controlled server.
Charming Kitten, also known as APT35, Cobalt Illusion, Educated Manticore, ITG18, Mint Sandstorm (formerly Phosphorus), TA453, and Yellow Garuda, is an Iranian state-owned APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC).
Over the years, the group has used various means to deploy backdoors in systems belonging to a wide range of industries.
This development comes as the threat actor was attributed by Microsoft to retaliatory attacks targeting critical infrastructure entities in the US between late 2020 and mid-2022, using specially designed malware such as CharmPower, Drokbk, and Soldier.
See also: Ukrainian sold data of 300 million citizens to Russians
Earlier this week, Check Point revealed that Mint Sandstorm had used an updated version of the PowerLess implant to target organizations located in Israel via Iraq.
The exact modus operandi used to achieve the initial intrusion has not yet been determined, although it is suspected to involve exploiting known vulnerabilities in applications exposed online, such as Microsoft Exchange Server or Zoho ManageEngine.
After a successful compromise, the threat actor attempts to disable Microsoft Defender using a PowerShell command and create persistence on the host via a service instance.
Bitdefender said it had also observed that Charming Kitten was downloading two Internet Information Services (IIS) modules, which were capable of processing incoming instructions and stealing credentials.
See also: PrestaShop fixes a bug that allows any backend user to delete databases

BellaCiao, for its part, is notable for performing a DNS request every 24 hours to resolve a sub-domain to an IP address, which is then parsed to extract the commands to be executed on the compromised system.
It communicates with an attacker-controlled DNS server that sends malicious, hard-coded instructions via a resolved IP address that mimics the target's real IP address. The result is additional malware being dropped via hard-coded instructions instead of traditional downloads.
Depending on the IP address that is resolved, the attack chain leads to the deployment of a web shell that supports the ability to upload and download arbitrary files, as well as execute commands.
See also: PaperCut servers attacks: Clop & Lockbit ransomware gangs are responsible
Additionally, a second variant of BellaCiao has been identified, which replaces the web shell with Plink – a command-line utility for PuTTY – designed to create a reverse proxy connection to a remote server and implement similar backdoor features.
The campaign, which has targeted a multitude of industries and company sizes, is believed to be the result of opportunistic attacks, where BellaCiao is adapted and deployed against carefully selected victims of interest after indiscriminately exploiting vulnerable systems.
Information source: thehackernews.com
