Malware hunters at Microsoft on Wednesday warned that an APT with known links to Iran's military intelligence has been impersonating a prominent journalist to trick a specific set of people into downloading malicious files.
The bespoke spear-phishing attacks, ongoing since November last year, are targeting high-profile individuals working on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the United Kingdom, and the United States.
In some instances of this campaign, Microsoft researchers caught the hackers using legitimate but compromised accounts to send phishing lures, and utilization of the Client for URL command to connect to its command-and-control server.
The APT has been caught masquerading as high-profile individuals, including as an unidentified journalist at a reputable news outlet.
Microsoft said the hacking team found success at certain targets that agreed to review the article or document referenced in the initial email.
This Cyber News was published on www.securityweek.com. Publication date: Wed, 17 Jan 2024 18:43:04 +0000