The Iranian hacking group Tortoiseshell is behind new watering hole attacks designed to deploy a malware called IMAPLoader.

See also: Iranian OilRig hackers stayed in a Middle Eastern government network for 8 months
What PwC Threat Intelligence says about Tortoiseshell and its techniques
"IMAPLoader is a .NET malware capable of decrypting and creating clones on Windows operating systems. A replacement for the former IMAP, based on the Python programming language, the updated IMAPLoader, using native services provided by Microsoft, pretends to be one of them, such as a downloader," PwC Threat Intelligence tells us in its analysis.
The analysis, in fact, tells us that "It regains control by using its controlled channels to search for encrypted IMAP email accounts. The Tortoiseshell group then manages to impersonate the downloader to extract and retrieve executable files and data from email ."
See also: Record cyberattacks against small businesses
Where do malware attacks end up?
The Tortoiseshell group was also detected using well-known "phishing" websites, targeting the medical and travel sectors, primarily in Europe.
With these methods and a history full of espionage and strategically important malware attacks on Israeli services and websites, related to financial, accounting and transportation purposes, Tortoiseshell hackers steal "golden" information.
Between 2022 and 2023, the Tortoiseshell team hacked into the JavaScript code of approved Israeli websites and collected detailed information about their visitors, their devices, and even their arrival times.
See also: Apple and Google have disabled live traffic maps in Israel and Gaza
The Tortoiseshell group has been active since 2018 and is aligned with the Islamic Revolutionary Guard Corps (IRGC), a special forces unit of Iran's military. It is worth mentioning that the nicknames, confirmed by the globally recognized cybersecurity community, are Crimson Sandstorm (formerly Curium), Imperial Kitten, TA456 and finally Liderc.

See also: Iranian hackers target organizations with password sprayingattacks
Iranian hackers, persistent and consistent with their attacks, tend to threaten many industries in Mediterranean countries with the aforementioned purposes and more. The malware attacks launched by the Tortoiseshell group seem to cross entire oceans and affect the nuclear, aerospace and defense industries of the US. They seem to show no mercy even to IT management service providers in the Middle East, where they belong.
Source: thehackernews.com
