The ongoing research work launched by the Rocket Kittens, which is one of the biggest threats on the internet, consists of two campaigns indicative of the group's evolving capabilities.
The first of these campaigns has already been exposed on 31C3 by Tillman Werner and Gadi Evron. This campaign, traditionally initiated through spear phishing emails, uses social engineering to entice targeted users to open a Microsoft Office.
Once the file is opened, the user is asked to allow macros to view the contents. If the user does so, a decoy file is displayed while their computer is infected with the GHOLE, allowing Rocket Kittens to gain remote access to their computer and infiltrate the target's corporate network.
Although this technique works for unsuspecting users, the attacker's perspective is different, where things are somewhat frustrating, as user interaction is required for the plan to succeed.
This is probably why the attackers launched the new campaign under the title “Operation Woolen-Goldfish”, which presents a significant improvement in terms of the TTP (Tactics, Techniques, and Procedures) developed by Rocket Kittens.
First, the content of the spear phishing has improved, we have seen in the past the Rocket Kittens abusing the identities of prominent Israeli figures and using exclusive content created from these profiles as a decoy file.
In an additional change, also related to the breach design, the spear phishing emails contain a link to a site, stored on a free online service. The stored file is compressed and contains an executable file that is supposed to be a Power Point.
Once this executable is clicked, it infects the target with a brand new malware, TSPY_WOOLERG.A , created by group member wool3n.h4t, who was already active in the first campaign.
The latest campaign, like the previous one, shows that the targets are particularly related to the Islamic Republic of Iran. While the motivations behind the attacks may differ, the end result is the same: shifting control of power, whether political or economic.

