HomeSecurityCyber ​​Espionage: Iranian Hackers Scarred Manticore Target Organizations in the Middle East

Cyberespionage: Iranian hackers Scarred Manticore target organizations in the Middle East

Iranian hackers Scarred Manticore are behind a cyber espionage against high-profile organizations in the Middle East, particularly in the government, military, and telecommunications sectors. Their targets also include IT service providers, financial institutions, and non-governmental organizations (NGOs). Scarred Manticore is affiliated with the country's Ministry of Intelligence and Security (MOIS).

Iranian hackers Scarred Manticore

The campaign was discovered by Check Point Research (CPR) and Sygnia's Incident Response Team and peaked in mid-2023. The hackers had gone undetected for at least a year.

See also: Cyber ​​espionage: YoroTrooper hackers may be related to Kazakhstan

According to Check Point, Iranian hackers Scarred Manticore routinely target high-value organizations, using various Internet Information Services (IIS)-based backdoors to infiltrate Windows. Their primary goal is espionage, but some of their tools were linked to a devastating attack on Albanian government infrastructure (related to DEV-0861).

In this latest campaign, the group used the LIONTAIL framework, a complex set of custom loaders and memory-resident shell code payloads. These implants use functions of the HTTP.sys driver to extract payloads from incoming HTTP traffic, allowing their malicious activities to be combined with legitimate network traffic.

The LIONTAIL framework is unique, with no clear code overlap with known malware families .Some tools used in the cyberespionage campaign resemble those of previous activities linked to the OilRig or OilRig affiliates. However, researchers say it is difficult to directly link Scarred Manticore to OilRig.

See also: International Criminal Court: Recent cyberattack was aimed at espionage

According to Check Point, the evolution of the tools and capabilities of the Scarred Manticore hackers indicates the progress that Iranian hackers have made in general in recent years. Their most recent attacks are much more sophisticated than their previous ones.

We expect that Scarred Manticore’s operations will continue and may expand to other regions in line with Iran’s long-term interests,” Check Point said.

Cyber ​​espionage

While most of Scarred Manticore's recent activity has focused primarily on maintaining covert access and extracting data, the disturbing example of the attack on Albanian government networks serves as a reminder that state hackers can collaborate and share access with their counterparts in intelligence agencies.“.

The motives of the Scarred Manticore hacking group are primarily related to political espionage. Scarred Manticore often targets political organizations, governments , and embassies, with the aim of obtaining information that they can use to influence politics and geopolitical relations.

See also: Grayling: New hacking group behind cyber espionage campaign

Additionally, the Scarred Manticore group may have financial motives. It targets businesses and organizations with the aim of stealing confidential information, such as copyrights, trade secrets, and customer. This information can be sold to competitors.

Finally, the Scarred Manticore group may have geopolitical motives. Their attacks may target countries or organizations that represent geopolitical interests that are opposed to Iran's.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS