HomeSecurityIranian Tortoiseshell group launches new waves of IMAPLoader Malware attacks

Iranian Tortoiseshell Group Launches New Waves of IMAPLoader Malware Attacks

The Iranian hacking group Tortoiseshell is behind new watering hole attacks designed to deploy a malware called IMAPLoader.

Iranian Tortoiseshell Group Launches New Waves of IMAPLoader Malware Attacks

See also: Iranian OilRig hackers stayed in a Middle Eastern government network for 8 months

What PwC Threat Intelligence says about Tortoiseshell and its techniques

"IMAPLoader is a .NET malware capable of decrypting and creating clones on Windows operating systems. A replacement for the former IMAP, based on the Python programming language, the updated IMAPLoader, using native services provided by Microsoft, pretends to be one of them, such as a downloader," PwC Threat Intelligence tells us in its analysis.   

The analysis, in fact, tells us that "It regains control by using its controlled channels to search for encrypted IMAP email accounts. The Tortoiseshell group then manages to impersonate the downloader to extract and retrieve executable files and data from email ."

See also: Record cyberattacks against small businesses

Where do malware attacks end up?

The Tortoiseshell group was also detected using well-known "phishing" websites, targeting the medical and travel sectors, primarily in Europe.

With these methods and a history full of espionage and strategically important malware attacks on Israeli services and websites, related to financial, accounting and transportation purposes, Tortoiseshell hackers steal "golden" information.

Between 2022 and 2023, the Tortoiseshell team hacked into the JavaScript code of approved Israeli websites and collected detailed information about their visitors, their devices, and even their arrival times.

See also: Apple and Google have disabled live traffic maps in Israel and Gaza

The Tortoiseshell group has been active since 2018 and is aligned with the Islamic Revolutionary Guard Corps (IRGC), a special forces unit of Iran's military. It is worth mentioning that the nicknames, confirmed by the globally recognized cybersecurity community, are Crimson Sandstorm (formerly Curium), Imperial Kitten, TA456 and finally Liderc.

tortoiseshell

See also: Iranian hackers target organizations with password sprayingattacks

Iranian hackers, persistent and consistent with their attacks, tend to threaten many industries in Mediterranean countries with the aforementioned purposes and more. The malware attacks launched by the Tortoiseshell group seem to cross entire oceans and affect the nuclear, aerospace and defense industries of the US. They seem to show no mercy even to IT management service providers in the Middle East, where they belong.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS