Also available in Persian — نسخه فارسی EN فا
❓ Unknown

Israeli Media Targeted by Malware Developed by Iranian-Linked Hackers

Feb 7, 2026 February 7, 2026 2 min read 📰 VOA Persian
📋 Key Takeaway

Iranian-linked hackers, part of APT35, have targeted Israeli media with sophisticated spear-phishing attacks, using updated malware called PowerStar. This incident highlights the ongoing cyber threats posed by Iranian state-affiliated groups against foreign entities, particularly in the context of geopolitical tensions.

🔍 Quick Context Guide
💡 Bottom Line: Iranian cyber operations continue to pose significant threats to foreign entities, particularly in the context of ongoing geopolitical rivalries.

👥 Key Players

APT35 MENTIONED
Iranian-linked hacking group
"APT35 is known for conducting cyber espionage and attacks, particularly against foreign entities, which reflects Iran's broader strategy of using cyber capabilities to assert influence and gather intelligence."
Volexity MENTIONED
Virginia-based security company
"Volexity provides critical insights into cyber threats and has identified the tactics and tools used by APT35, contributing to the understanding of Iranian cyber operations."
Israeli media MENTIONED
Target of the cyber attack
"The Israeli media plays a significant role in shaping public opinion and policy in Israel, making it a strategic target for Iranian cyber operations."

📰 What Happened

Iranian-linked hackers from APT35 conducted sophisticated spear-phishing attacks against Israeli media, using updated malware named PowerStar to gain access to journalists' devices. The attacks involved deceptive tactics to build trust before delivering malicious content.

  • The malware used, PowerStar, is an updated version of CharmPower and includes advanced features to evade detection.
  • APT35 has been active for about a decade, focusing on social engineering methods to carry out their cyber attacks.

💡 Why It Matters

🇮🇷 For Iran: This incident demonstrates Iran's capability and willingness to engage in cyber warfare, reinforcing its strategy of using technology for espionage and influence.
🌍 Regional: The attack highlights the escalating cyber conflict in the region, which may lead to increased tensions between Iran and Israel.
🌐 International: Internationally, this incident raises concerns about the security of media organizations and the potential for misinformation campaigns linked to cyber attacks.

📚 Background

Iran has increasingly relied on cyber capabilities as a tool for espionage and influence, particularly against adversaries like Israel. APT35 is one of several groups linked to the Iranian government that conducts cyber attacks.

Cyber warfare Iran-Israel relations
📡 Source: NEUTRAL
📊 Confidence: 70%
The article is based on reports from security experts and provides factual information about the cyber attack without overt bias.

A group of government hackers affiliated with the Islamic Republic and part of a group known as APT35, previously recognized by names such as Charming Kitten, Imperial Kitten, and Tortoiseshell, have updated their tools and capabilities and conducted a series of targeted deceptive attacks, known as spear-phishing, against various accounts and emails, including individuals in Israel. The Virginia-based security company Volexity stated that in one instance of phishing attacks, this group sent a compressed RAR file titled 'Draft Report' to an Israeli journalist. This password-protected file directs the victim to a malicious link, granting the attackers access to the victim's device. According to the company, the hackers acted very purposefully in this case. They asked the journalist if they would like to read a document related to U.S. foreign policy. The hackers then indirectly sent harmless questions to the victim through another email and interacted with them for several days before ultimately sending the infected file 'Draft Report' to gain their trust. The malware used by the hackers during this phishing attack is named PowerStar. This malware is essentially an updated version of another malware called CharmPower, which the security company Check Point reported on extensively last year. During the infection of the target device, this malware utilizes services from Backblaze and transfers and stores the victim's information through command and control (C2). Investigations by Volexity experts have shown that the hackers have developed this malware in a way that automates simple operator actions. Additionally, a decryption function for remotely hosted files and a malware shutdown button have been added to make detecting the malware outside of memory difficult and to prevent future analysis of its key functions. According to these experts, the hackers use this developed malware in a limited manner, making it harder to monitor and analyze the malware's performance and its operators. APT35 hackers have been under the scrutiny of security companies for about a decade, and in 2021, Darktrace published a detailed report on this group's attacks in the Middle East and North America. Toby Lewis, the global threat analysis director at Darktrace, stated that this group linked to the Iranian government always strives to appear unique and distinct and hides from any monitoring. Therefore, they have chosen and focused on social engineering methods for their activities.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →