{"id":2385,"date":"2024-01-19T17:30:00","date_gmt":"2024-01-19T17:30:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-iran-mint-sandstorm-apt-blasts-educators-researchers"},"modified":"2024-01-19T17:30:00","modified_gmt":"2024-01-19T17:30:00","slug":"microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/19\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers\/","title":{"rendered":"Microsoft: Iran&#8217;s Mint Sandstorm APT Blasts Educators, Researchers"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt46b6dd4de5807065\/65aab399aa1190040a70099f\/Sandstorm_Zoonar_GmbH_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Iran-linked Mint Sandstorm group is targeting Middle Eastern affairs specialists at universities and research organizations with convincing social engineering efforts, which conclude by delivering malware and compromising victims&#8217; systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The latest espionage campaign by the Mint Sandstorm group, which has ties to the Iranian military, aims to steal information from journalists, researchers, professors, and other professionals who cover security and policy topics of interest to the Iranian government.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/01\/17\/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">a Microsoft advisory<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> out this week, the cyber-espionage group uses lures related to the Israel-Hamas war, leading Microsoft to conclude that the group likely intends to gather intelligence on and perspectives about that conflict from policy experts.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group is well known for its persistent and sustained efforts, the analysis stated.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">&#8220;Patient &amp; Highly Skilled Social Engineers&#8221;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mint Sandstorm is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/threat-actor-names-proliferate-adding-confusion\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Microsoft&#8217;s name<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for a collection of cyber-operations teams linked to the Islamic Revolutionary Guard Corps (IRGC), an intelligence arm of Iran&#8217;s military.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group overlaps with threat actors known as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/iran-linked-apt35-israeli-media-upgraded-spear-phishing\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">APT35<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Google&#8217;s Mandiant and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/irans-charming-kitten-israeli-exchange-servers\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Charming Kitten<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Crowdstrike; the latest espionage campaign is likely run by a &#8220;technically and operationally mature subgroup of Mint Sandstorm,&#8221; the company said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails,&#8221; Microsoft Threat Intelligence stated in the analysis. &#8220;In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group is well known for sophisticated social engineering campaigns, according to Secureworks, which considers Microsoft&#8217;s Mint Sandstorm to most closely align with the group Secureworks&#8217; Counter Threat Unit (CTU) calls &#8220;Cobalt Illusion.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group regularly conducts surveillance and espionage activities against those considered to be a threat to the Iranian government \u2014 for example, targeting researchers documenting the suppression of women and minority groups last year, says Rafe Pilling, director of threat research for the CTU.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Any institutions or researchers that study topics of strategic or political interest to the government of Iran or their subordinate intelligence functions could be a target,&#8221; he says. &#8220;We&#8217;ve seen journalists and academic researchers that cover Iranian and Middle Eastern political, policy and security issues being targeted as well as IGOs and NGOs that work within Iran or in areas of interest to Iran.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Impersonators Extraordinaire<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group frequently conducts resource-intensive <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/social-engineering-drives-bec-losses-to-50b-globally\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">social engineering <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">campaigns against targeted groups or individuals, much like the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/russia-coldriver-apt-unleashes-custom-spica-malware\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Russian APT group ColdRiver,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> also the subject of threat intelligence analysis this week. Adopting the mien of journalists or known researchers is a typical tactic of Mint Sandstorm, and targeting educational institutions has also taken off.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Typically, Mint Sandstorm will engage with the targeted individual in the guise of requesting an interview or initiating a conversation about specific topics, eventually manipulating the email thread to the point that the individual can be convinced to click on a link, Secureworks&#8217; Pilling says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If the group can steal credentials for an email account, it will often use that to better pose as a legitimate journalist or researcher, Pilling says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Actually compromising the email account of a journalist to then target other individuals is much less common but not unheard of,&#8221; he says. &#8220;Some state-sponsored groups will compromise organizations that their targets work with to send phishing attacks that are more likely to be trusted by their real target.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Custom Backdoors for Cyber-Espionage<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once the attackers have gained rapport with their target, they send an email containing a link to a malicious domain, often leading to a RAR archive file that they claim contains a draft document for review. Through a series of steps, the attackers would eventually drop one of two custom backdoor programs: MediaPI, which poses as Windows Media Player, or MischiefTut, a tool written in PowerShell.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Mint Sandstorm continues to improve and modify the tooling used in targets&#8217; environments, activity that might help the group persist in a compromised environment and better evade detection,&#8221; Microsoft stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Nation-state-backed groups and financially motivated cybercriminals often share techniques, so the use of custom backdoor is a notable, Callie Guenther, a senior manager for cyber-threat research at Critical Start, wrote in a statement.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The spread of these tactics could signal an overall escalation in the cyber-threat landscape,&#8221; she said. &#8220;What begins as a targeted, geopolitically motivated attack could evolve into a more widespread threat, affecting a larger number of organizations and individuals.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-iran-mint-sandstorm-apt-blasts-educators-researchers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Iran-linked Mint Sandstorm group is targeting Middle Eastern affairs<\/p>\n","protected":false},"author":12,"featured_media":2386,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2385","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/microsoft-irans-mint-sandstorm-apt-blasts-educators-researchers.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2385","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2385"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2385\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2386"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2385"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2385"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}