Since at least September 2023, the Iranian threat actor known as TA455 has been seen using a North Korean hacker collective’s strategy to plan its own version of the Dream Job campaign, which targets the aerospace sector by offering fictitious opportunities.
According to an investigation released on Tuesday by Israeli cybersecurity firm ClearSky, the campaign disseminated the SnailResin virus, which opens the SlugResin backdoor.
TA455, also tracked by Google-owned Mandiant as UNC1549 and Yellow Dev 13, is considered to be a sub-cluster within APT35, which is known by the names CALANQUE, Charming Kitten, CharmingCypress, ITG18, Mint Sandstorm (previously Phosphorus), Newscaster, TA453, and Yellow Garuda.
Connected to the Islamic Revolutionary Guard Corps (IRGC) of Iran read more about Iranian Hackers Use “Dream Job” Lures to Deploy SnailResin Malware in Aerospace Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
