An Iranian hacking gang, known as TA455, has been seen taking inspiration from a hacking gang to organize its own “Dream Job”.

This campaign targets the aerospace industry with fake job postings starting at least September 2023.
According to an analysis by Israeli cybersecurity firm ClearSky, “the campaign distributes the SnailResin malware,which activates the backdoor .”
Read more: Russian hacking gang Gamaredon remains active in Ukraine
TA455, which is also tracked by Google through Mandiant as UNC1549 and Yellow Dev 13, is believed to be a subgroup of APT35, also known as CALANQUE, Charming Kitten, ITG18, etc. This group, which is affiliated with the Iranian Islamic Revolutionary Guard Corps, is said to have tactics reminiscent of groups such as Smoke Sandstorm and Crimson Sandstorm.
Earlier this year, this collective carried out a series of targeted attacks against the aerospace, aviation, and defense industries in the Middle East. These attacks exploit social engineering, offering jobs to install two backdoors, MINIBIKE and MINIBUS.

See more: Pro-Russian hacking groups attack South Korea
ClearSky identified several similarities between the two Dream Job campaigns run by the Lazarus group and TA455, including the use of job offers to spread malware. This raises the possibility that TA455 is either intentionally copying the North Korean hacking group’s tactics or engaging in some form of tool sharing.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
