Tag: Middle East and North Africa (MENA)

Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign
News

Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign

MuddyWater, an Iranian nation-state entity, has been implicated in a recent effort that used a hacked email account to spread a backdoor dubbed Phoenix to more than 100 government agencies and other organizations around the Middle East and North Africa (MENA) area. In a technical analysis released today, Singaporean cybersecurity firm Group-IB stated that the campaign's ultimate objective is to breach high-value targets and aid in the collection of intelligence. Embassies, diplomatic missions, foreign affairs ministries, and consulates make up over three-fourths of the campaign's targets, with international organizations and telecom companies coming in second and third. According to security experts Mahmoud Zohdy and Mansour Alhmoud, MuddyWater utilized NordVPN, a legitimate prov...
New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA
News

New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA

The Middle East and North Africa (MENA) and Asia-Pacific (APAC) financial institutions are the target of JSOutProx, a new "evolving threat" variant. In a technical paper released this week, Resecurity stated that "JSOutProx is an advanced attack framework that leverages both JavaScript and.NET." It interacts with a core JavaScript module that is operating on the victim's computer by using the.NET (de)serialization functionality. Once it's run, the malware allows the framework to load further plugins, which in turn carry out more harmful operations on the target. Early attacks dispersing JSOutProx were first discovered by Yoroi in December 2019 and have been linked to a threat actor known as Solar Spider. The history of bank strikes and other large company actions in Europe and As...