An Iran-linked group known as Homeland Justicehas been linked to a “coordinated” and “multi-wave” spear-phishing attack targeting embassies and consulates in Europe and other regions of the world. This activity has been attributed by Israeli cybersecurity firm Dream to operators aligned with Iran and linked to broader offensive activity.
See also: Iranian hackers leaked data of Saudi Games athletes

“The emails were sent to multiple government recipients worldwide, disguised as legitimate diplomatic communications,” the company said. “The evidence points to a broader regional espionage effort targeting diplomatic and government entities during a period of heightened geopolitical tension.”
The attack chains involve the use of spear-phishing emails with themes related to geopolitical tensions between Iran and Israel to send a malicious Microsoft Word that, when opened, prompts recipients to “Enable Content” to run an embedded Visual Basic for Applications (VBA) macro, which is responsible for deploying the malware.
According to Dream, the Homeland Justice emails were sent to embassies, consulates and international organizations in the Middle East, Africa, Europe, Asia and the Americas, indicating that the activity had a wide range of targets. European embassies and African organizations were said to have been the most heavily targeted. The digital messages were sent from 104 unique compromised addresses belonging to officials and pseudo-government entities to give them an extra layer of credibility. At least some of the emails originated from a compromised account belonging to the Omani Ministry of Foreign Affairs in Paris.
See also: Bloomberg: Iran hacks cameras to monitor Israelis

“The decoy content consistently referenced urgent MFA communications, transferred authority, and exploited the common practice of activating macros to access content, which are the hallmarks of a well-planned espionage operation that intentionally masked performance,” Dream reported.
The ultimate goal of the Homeland Justice attacks is to deploy an executable file using a VBA macro that can establish persistence, communicate with a command and control (C2) server, and collect system information. Cybersecurity firm ClearSky, which also analyzed some aspects of the campaign late last month, reported that the phishing emails were sent to multiple State Departments.
See also: Iranian hackers pose as German Model Agency
“Similar obfuscation techniques were used by Iranian threat actors in 2023 when they targeted the Mojahedin-e-Khalq in Albania,” he said in a post on X. “We assess with moderate confidence that this activity is linked to the same Iranian malicious actors.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
