{"id":2619,"date":"2024-02-28T02:00:00","date_gmt":"2024-02-28T02:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms"},"modified":"2024-02-28T02:00:00","modified_gmt":"2024-02-28T02:00:00","slug":"illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/28\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms\/","title":{"rendered":"&#8216;Illusive&#8217; Iranian Hacking Group Ensnares Israeli, UAE Aerospace and Defense Firms"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt46b6dd4de5807065\/65aab399aa1190040a70099f\/Sandstorm_Zoonar_GmbH_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An Iranian Revolutionary Guard Corps (IGRC)-linked threat group is staging political messaging and phony technical jobs to fool employees and compromise systems at aerospace and defense firms in Israel, the United Arab Emirates, and other countries in the greater Middle East.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign, discovered by Google Cloud&#8217;s Mandiant, appears to be linked to Iranian threat group UNC1549 \u2014 also known as Smoke Sandstorm and Tortoiseshell \u2014 and executes spear phishing and watering-hole attacks for credential harvesting and dropping malware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A successful compromise typically results in backdoor software installed on the affected systems, usually a program known as MINIBIKE or its more up-to-date cousin, MINIBUS.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Between the tailored employment-focused spear phishing and the use of cloud infrastructure for command-and-control, the attack may be difficult to detect, says Jonathan Leathery, principal analyst for Google Cloud&#8217;s Mandiant.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The most notable part is how illusive this threat can be to discover and track \u2014 they clearly have access to significant resources and are selective in their targeting,&#8221; he says. &#8220;There is likely more activity from this actor that is not yet discovered, and there is even less information on how they operate once they&#8217;ve compromised a target.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/iran-linked-muddywater-spies-middle-east-govt-eight-months\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Iranian threat groups<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have increasingly targeted sensitive industries to glean government secrets and intellectual property. In 2021, Microsoft noted a dramatic shift, for example, of Iran-linked cyber-operations groups focusing on IT services firms as a way to leapfrog into the networks of government clients. The company detected intrusions and sent out <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/11\/18\/iranian-targeting-of-it-sector-on-the-rise\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">1,647 notices to IT services firms<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> after detecting Iran-based actors targeting them, a massive jump from just 48 such notices sent by Microsoft in 2020.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Smoke and Malware\">Smoke and Malware<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft noted that Smoke Sandstorm \u2014 its name for the group \u2014 had compromised the email accounts of a Bahrain-based IT integrator in 2021, likely as a way to gain access to the firm&#8217;s government clients. Microsoft <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/security-insider\/#threat-watch\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">disrupted some of the group&#8217;s spear phishing operations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in May 2022.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the Tortoiseshell group \u2014 also known as UNC1549 by Google and Imperial Kitten by CrowdStrike \u2014&nbsp;continues to focus on IT service providers, the group now also wages watering-hole attacks and spear phishing as its primary initial infection tactics.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat group has since regrouped, however, and as of February 2024, is targeting aerospace, aviation, and defense firms in Israel and UAE, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.mandiant.com\/resources\/blog\/suspected-iranian-unc1549-targets-israel-middle-east\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">Google stated in its analysis<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The group may also be connected to cyberattacks on similar industries in Albania, India, and Turkey.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The intelligence collected on these entities is of relevance to strategic Iranian interests, and may be leveraged for espionage as well as kinetic operations,&#8221; Google wrote. &#8220;This is further supported by the potential ties between UNC1549 and the Iranian IRGC.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The spear phishing messages send links to websites that appear to either be a job site \u2014 specifically focusing on technology- and defense-related positions \u2014 or part of the &#8220;Bring Them Home Now&#8221; movement calling for the return of Israeli hostages.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attack chain eventually leads to the download of one of two unique backdoors to the victim&#8217;s system. MINIBIKE is a C++ program designed as a backdoor, allowing the exfiltration or upload of data, as well as command execution. MINIBUS, its newer variant, includes more flexibility and &#8220;enhanced reconnaissance features,&#8221; according to Google.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Customized Cyberattacks\">Customized Cyberattacks<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The UNC1549 group appears to do significant reconnaissance and preparation prior to attacks, including reserving domain names that are matched to the targeted group. Because of the level of custom content created for each targeted firm, the total number of targeted organizations is hard to estimate, Leathery says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The data suggests they identify specific targets [and] then likely shape their strategy around the target \u2014&nbsp;for instance, they register domains that relate directly to a specific target,&#8221; he says. &#8220;In many instances they include decoy content that has to be created or researched [or] repurposed from publicly available legitimate information.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Google Cloud&#8217;s Mandiant rated the attribution as &#8220;medium&#8221; confidence, which means the threat researchers believe that it&#8217;s very likely that the activity was carried out by the UNC1549 group.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We think it is very likely that UNC1549 conducted it, but there is not enough evidence to rule out that it could have been a different group,&#8221; he says. &#8220;However, even in these unlikely circumstances, we think it is simply a different group operating in support of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/the-no-good-very-bad-week-for-iran-s-nation-state-hacking-ops\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Iranian government<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Beware Email Links and Suspicious Beaconing\">Beware Email Links and Suspicious Beaconing<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In its technical analysis, Google details specific indicators of compromise (IOCs) for the MINIBIKE malware, including its use of four Azure domains for its command and control, a OneDrive registry key to maintain persistence, and beacon communications cycling over three filenames mimicking Web components.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The newer MINIBUS, meanwhile, is more compact and flexible. Google lists a number of DLL filenames that could be in use and warns that the malware tries to detect whether it is running on a virtual machine as well as whether security applications are running.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With UNC1549&#8217;s reliance on researching targets and customized spear phishing, companies should block untrusted links in emails and lean into awareness training to keep their employees up to date on the latest phishing methods, according to Google.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An Iranian Revolutionary Guard Corps (IGRC)-linked threat group is staging<\/p>\n","protected":false},"author":12,"featured_media":2620,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2619","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/illusive-iranian-hacking-group-ensnares-israeli-uae-aerospace-and-defense-firms.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2619"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2619\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2620"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}