Tag: Iranian

New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE Government
News

New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE Government

An anonymous United Arab Emirates (UAE) government organisation was the target of a "simple yet effective" backdoor known as PowerExchange that was presumably created by an Iranian threat actor. A recent study from Fortinet FortiGuard Labs claims that the intrusion used email phishing as its initial access point and resulted in the execution of a.NET executable that was attached as a ZIP file. The malware, which pretends to be a PDF file, serves as a dropper for the final payload to run, which ultimately starts the backdoor read more New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE Government. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.
Iranian Tortoiseshell Hackers Targeting Israeli Logistics Industry
News

Iranian Tortoiseshell Hackers Targeting Israeli Logistics Industry

At least eight websites associated with shipping, logistics, and financial services companies in Israel were targeted as part of a watering hole attack. Tel Aviv-based cybersecurity company ClearSky attributed the attacks with low confidence to an Iranian threat actor tracked as Tortoiseshell, which is also called Crimson Sandstorm (previously Curium), Imperial Kitten, and TA456. "The infected sites collect preliminary user information through a script," ClearSky said in a technical report published Tuesday read more Iranian Tortoiseshell Hackers Targeting Israeli Logistics Industry. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.
BouldSpy Android Spyware: Iranian Government’s Alleged Tool for Spying on Minority Groups
News

BouldSpy Android Spyware: Iranian Government’s Alleged Tool for Spying on Minority Groups

Over 300 members of minority groups have been spied on using a new Android surveillance app that the Iranian government may use. The Law Enforcement Command of the Islamic Republic of Iran (FARAJA) has been tentatively linked to the virus, known as BouldSpy. Iranian Kurds, Baluchis, Azeris, and Armenian Christian organizations are among the groups targeted. Based on data that was exfiltrated and featured images of drugs, weapons, and official FARAJA documents, Lookout speculated that the spyware may have been used to combat and monitor illegal trading in all three areas read more BouldSpy Android Spyware Iranian Government's Alleged Tool for Spying on Minority Groups. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity tren...