A group of government hackers affiliated with the Islamic Republic and part of a group known as APT35, previously recognized by names such as Charming Kitten, Imperial Kitten, and Tortoiseshell, have updated their tools and capabilities and conducted a series of targeted deceptive attacks, known as spear-phishing, against various accounts and emails, including individuals in Israel. The Virginia-based security company Volexity stated that in one instance of phishing attacks, this group sent a compressed RAR file titled 'Draft Report' to an Israeli journalist. This password-protected file directs the victim to a malicious link, granting the attackers access to the victim's device. According to the company, the hackers acted very purposefully in this case. They asked the journalist if they would like to read a document related to U.S. foreign policy. The hackers then indirectly sent harmless questions to the victim through another email and interacted with them for several days before ultimately sending the infected file 'Draft Report' to gain their trust. The malware used by the hackers during this phishing attack is named PowerStar. This malware is essentially an updated version of another malware called CharmPower, which the security company Check Point reported on extensively last year. During the infection of the target device, this malware utilizes services from Backblaze and transfers and stores the victim's information through command and control (C2). Investigations by Volexity experts have shown that the hackers have developed this malware in a way that automates simple operator actions. Additionally, a decryption function for remotely hosted files and a malware shutdown button have been added to make detecting the malware outside of memory difficult and to prevent future analysis of its key functions. According to these experts, the hackers use this developed malware in a limited manner, making it harder to monitor and analyze the malware's performance and its operators. APT35 hackers have been under the scrutiny of security companies for about a decade, and in 2021, Darktrace published a detailed report on this group's attacks in the Middle East and North America. Toby Lewis, the global threat analysis director at Darktrace, stated that this group linked to the Iranian government always strives to appear unique and distinct and hides from any monitoring. Therefore, they have chosen and focused on social engineering methods for their activities.
Israeli Media Targeted by Malware Developed by Iranian-Linked Hackers
Iranian-linked hackers, part of APT35, have targeted Israeli media with sophisticated spear-phishing attacks, using updated malware called PowerStar. This incident highlights the ongoing cyber threats posed by Iranian state-affiliated groups against foreign entities, particularly in the context of geopolitical tensions.
👥 Key Players
📰 What Happened
Iranian-linked hackers from APT35 conducted sophisticated spear-phishing attacks against Israeli media, using updated malware named PowerStar to gain access to journalists' devices. The attacks involved deceptive tactics to build trust before delivering malicious content.
- The malware used, PowerStar, is an updated version of CharmPower and includes advanced features to evade detection.
- APT35 has been active for about a decade, focusing on social engineering methods to carry out their cyber attacks.
💡 Why It Matters
📚 Background
Iran has increasingly relied on cyber capabilities as a tool for espionage and influence, particularly against adversaries like Israel. APT35 is one of several groups linked to the Iranian government that conducts cyber attacks.
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%