In recent months, a surge in targeted attacks attributed to the Iran-linked APT35 threat group has raised alarm bells in government and military networks worldwide. The campaign, first detected in early 2025, uses malware specifically crafted to infiltrate secure environments and harvest user credentials.
See also: Hackers try to exploit vulnerability in PAN-OS GlobalProtect

Initial signs of a breach point to spear-phishing emails with HTML attachments that deploy a multi-layered payload once opened, silently installing a foothold in the target's environment.
Analysis of the attack chain reveals that the initial vector often includes weaponized Microsoft Office documents that exploit CVE-2023-23397 to bypass Outlook's security model. The embedded code downloads a PowerShell stager, which then retrieves the main credential theft module from a remote command and control (C2) server.
Stromshield researchers spotted this behavior during a Department of Defense network breach in April, noting the seamless transition from document exploitation to silent identification and credential extraction.
Once deployed, the malware pretends to be legitimate system processes to evade detection. It hooks into the Windows Security Support Interface (SSPI) to intercept NTLM challenge-response exchanges, recording hashed credentials in memory.
These hashes are then transferred to the attacker's infrastructure, where a combination of hash cracking and pass-the-hash techniques unlocks privileged accounts on high-value servers.
See also: Hackers approached BBC journalist for help in hack

The impact was significant: many accounts within military communication networks were compromised without triggering conventional intrusion detection systems.
The infection mechanism is based on a two-stage downloader that first discerns the victim's environment. After successfully exploiting the document, the initial stager performs environment checks for security tools and scans loaded kernel modules.
If a recognized analysis sandbox is detected, execution stops to prevent reverse engineering attempts. Otherwise, the stager decodes a base64-encoded second-stage payload, writes it to %AppData%\Roaming\msnetcache.dll before loading it via rundll32.exe.
This DLL implements the SSPI hook logic, intercepts credentials, and then executes HTTP GET requests to the C2 domain over port 443, mixing the traffic with legitimate HTTPS sessions.
Overall, the campaign reflects APT35's increasing sophistication in embedding itself deep within trusted processes and leveraging native APIs to capture credentials without leaving visible artifacts.
See also: RedNovember breached critical infrastructure worldwide
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Constant vigilance and advanced behavioral monitoring are critical to detecting such silent intrusions before critical access is compromised.
