HomeSecurityIranian Homeland Justice Targets Over 100 Embassy Emails

Iranian Homeland Justice Targets Over 100 Embassy Emails

An Iran-linked group known as Homeland Justicehas been linked to a “coordinated” and “multi-wave” spear-phishing attack targeting embassies and consulates in Europe and other regions of the world. This activity has been attributed by Israeli cybersecurity firm Dream to operators aligned with Iran and linked to broader offensive activity.

See also: Iranian hackers leaked data of Saudi Games athletes

Homeland Justice
Iranian Homeland Justice Targets Over 100 Embassy Emails

“The emails were sent to multiple government recipients worldwide, disguised as legitimate diplomatic communications,” the company said. “The evidence points to a broader regional espionage effort targeting diplomatic and government entities during a period of heightened geopolitical tension.”

The attack chains involve the use of spear-phishing emails with themes related to geopolitical tensions between Iran and Israel to send a malicious Microsoft Word that, when opened, prompts recipients to “Enable Content” to run an embedded Visual Basic for Applications (VBA) macro, which is responsible for deploying the malware.

According to Dream, the Homeland Justice emails were sent to embassies, consulates and international organizations in the Middle East, Africa, Europe, Asia and the Americas, indicating that the activity had a wide range of targets. European embassies and African organizations were said to have been the most heavily targeted. The digital messages were sent from 104 unique compromised addresses belonging to officials and pseudo-government entities to give them an extra layer of credibility. At least some of the emails originated from a compromised account belonging to the Omani Ministry of Foreign Affairs in Paris.

See also: Bloomberg: Iran hacks cameras to monitor Israelis

Iranian Homeland Justice Targets Over 100 Embassy Emails
Iranian Homeland Justice Targets Over 100 Embassy Emails

“The decoy content consistently referenced urgent MFA communications, transferred authority, and exploited the common practice of activating macros to access content, which are the hallmarks of a well-planned espionage operation that intentionally masked performance,” Dream reported.

The ultimate goal of the Homeland Justice attacks is to deploy an executable file using a VBA macro that can establish persistence, communicate with a command and control (C2) server, and collect system information. Cybersecurity firm ClearSky, which also analyzed some aspects of the campaign late last month, reported that the phishing emails were sent to multiple State Departments.

See also: Iranian hackers pose as German Model Agency

“Similar obfuscation techniques were used by Iranian threat actors in 2023 when they targeted the Mojahedin-e-Khalq in Albania,” he said in a post on X. “We assess with moderate confidence that this activity is linked to the same Iranian malicious actors.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS