Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- Opinion | Wasnt Hell Supposed to Break Loose if the U.S. Struck Iran? - The Wall Street Journal - September 13th, 2025 [September 13th, 2025]
- After wedding was canceled due to Iran war, Avner Netanyahu calls off his engagement - The Times of Israel - September 13th, 2025 [September 13th, 2025]
- Iran-Contra figures Oliver North and Fawn Hall marry after 40 years - BBC - September 13th, 2025 [September 13th, 2025]
- What Israel's Unprecedented Strike In Qatar Means For Iran And The Region - Radio Free Europe/Radio Liberty - September 13th, 2025 [September 13th, 2025]
- Nuclear watchdog hails new deal with Iran, but inspections remain on hold - RFI - September 13th, 2025 [September 13th, 2025]
- Caught in the Crossfire: Jordans Balancing Act in the Iran-Israel Conflict - The Cairo Review of Global Affairs - September 13th, 2025 [September 13th, 2025]
- G7 and Allies Warn Iran Over Unacceptable Overseas Kidnap and Harassment Campaigns - kurdistan24.net - September 13th, 2025 [September 13th, 2025]
- Australia and New Zealand voice support for Iranian women on Mahsa Amini anniversary | Iran International - - September 13th, 2025 [September 13th, 2025]
- Iranian Regime MPs Threaten Foreign Minister Araghchi Amid Nuclear Infighting - National Council of Resistance of Iran - NCRI - September 13th, 2025 [September 13th, 2025]
- Iran Says Withdrawal from NPT Remains an Option if Snapback Triggered - WANA News Agency - September 13th, 2025 [September 13th, 2025]
- Iran committed to developing sustainable, clean energy - Tehran Times - September 13th, 2025 [September 13th, 2025]
- Iran, Iraq sign MOU to beef up ties in combating narcotics - Tehran Times - September 13th, 2025 [September 13th, 2025]
- Salutes and anthems: how sports succumbed to Iran's culture war - - September 13th, 2025 [September 13th, 2025]
- Woman, Life, Freedom Uprising sparked social revolution in E.Kurdistan, Iran - ANHA - September 13th, 2025 [September 13th, 2025]
- Iran and Tunisia Forge New Path in Economic and Tourism Cooperation - Travel And Tour World - September 13th, 2025 [September 13th, 2025]
- US attack on Iran was sound but talks must win peace, ex-US diplomat says - - September 13th, 2025 [September 13th, 2025]
- Iran warns it will withdraw from fresh IAEA agreement if Europe invokes "snapback" sanctions - Peoples Dispatch - September 13th, 2025 [September 13th, 2025]
- Kordestan, a hidden treasure in west of Iran - Tehran Times - September 13th, 2025 [September 13th, 2025]
- Iran to take part in five intl. tourism fairs - Tehran Times - September 13th, 2025 [September 13th, 2025]
- US seizes nearly $600k in crypto from Iranian tied to IRGC drones | Iran International - - September 13th, 2025 [September 13th, 2025]
- Iran publishes footage and testimonies from 11-day conflict with Israel - Middle East Eye - September 11th, 2025 [September 11th, 2025]
- Nuclear watchdog chief announces breakthrough on Iran monitoring - Department of Political and Peacebuilding Affairs - September 11th, 2025 [September 11th, 2025]
- Iran, IAEA announce agreement on resuming nuclear inspections - Reuters - September 11th, 2025 [September 11th, 2025]
- War or Peace, Win or Lose TV satellite program in Iran started its encouraging work - Mission Network News - September 11th, 2025 [September 11th, 2025]
- Iran News in Brief September 11, 2025 - National Council of Resistance of Iran - NCRI - September 11th, 2025 [September 11th, 2025]
- The Clerical Regimes Endure and Suffer Tactic: Crushing Iran's Society Through Systemic Deprivation - National Council of Resistance of Iran - NCRI - September 11th, 2025 [September 11th, 2025]
- US offers $15 million reward over Iran's Revolutionary Guards network - - September 11th, 2025 [September 11th, 2025]
- Iran Arrests Three 17-Year-Olds, Transfers Them to Undisclosed Locations - IranWire - September 11th, 2025 [September 11th, 2025]
- New Trump Corridor Leaves Iran Scrambling to Preserve Influence in the South Caucasus - Stimson Center - September 11th, 2025 [September 11th, 2025]
- IAEA chief says agreement reached with Iran on resuming inspections - Anadolu Ajans - September 11th, 2025 [September 11th, 2025]
- Opinion: With Traditional Proxies Sidelined, Iran Sets Its Sights on Sudan - Philadelphia Jewish Exponent - September 11th, 2025 [September 11th, 2025]
- Iran says more talks needed to bring about IAEA inspections - Reuters - September 11th, 2025 [September 11th, 2025]
- Iran says deal with IAEA does not yet guarantee inspectors access to nuclear sites - The Times of Israel - September 11th, 2025 [September 11th, 2025]
- Iran-IAEA 'deal' on broader nuclear standoff unclear, with contradicting reports on inspections - The Jerusalem Post - September 11th, 2025 [September 11th, 2025]
- Israel and Iran: Major Threats to Middle East Stability - The Cairo Review of Global Affairs - September 11th, 2025 [September 11th, 2025]
- Iran Automotive Market - Ken Research Stated the Sector Valued at ~IRR 38 billion with Strong Growth Potential - openPR.com - September 11th, 2025 [September 11th, 2025]
- Explainer: What does the new agreement between Iran and IAEA entail - PressTV - September 11th, 2025 [September 11th, 2025]
- Iran, UN nuclear watchdog reach understanding on cooperation - KSL.com - September 11th, 2025 [September 11th, 2025]
- Iran and IAEA Seal Cairo Understanding To Restart Inspections - The Media Line - September 11th, 2025 [September 11th, 2025]
- Oliver North And Fawn Hall, Key Players In The Iran-Contra Scandal, Are Married - MSN - September 11th, 2025 [September 11th, 2025]
- 'Little Iran' signage coming to part of Yonge St. in October - MSN - September 11th, 2025 [September 11th, 2025]
- Iran will exchange nuclear monitoring for lifted sanctions, says its foreign minister - The Guardian - September 9th, 2025 [September 9th, 2025]
- After Israeli, US strikes, Europeans hope snapback threats push Iran to tougher nuclear deal - The Times of Israel - September 9th, 2025 [September 9th, 2025]
- IAEA chief notes progress in Iran talks over nuclear site inspections - Al Jazeera - September 9th, 2025 [September 9th, 2025]
- Iran Sends Warning Over Nuclear Sanctions - Newsweek - September 9th, 2025 [September 9th, 2025]
- Iran News in Brief September 9, 2025 - National Council of Resistance of Iran - NCRI - September 9th, 2025 [September 9th, 2025]
- Restoring IAEA Inspections in Iran Would Create Promising Ground for Wider Progress, Says Director General Grossi - IAEA - September 9th, 2025 [September 9th, 2025]
- Severe Water Crisis and Regular Blackouts Threaten to Push Iran to the Brink - cbn.com - September 9th, 2025 [September 9th, 2025]
- Iran Witnesses Protests Over Corruption, Repression, and State Failure - National Council of Resistance of Iran - NCRI - September 9th, 2025 [September 9th, 2025]
- Trump considers banning Iranian diplomats from shopping at Costco: Hit Iran where it hurts - Fox Business - September 9th, 2025 [September 9th, 2025]
- Iran Culture Ministry Official Fired After Backlash from Conservatives - IranWire - September 9th, 2025 [September 9th, 2025]
- Iran: Protests, Strikes in Semirom Following Execution of Political Prisoner Mehran Bahramian - National Council of Resistance of Iran - NCRI - September 9th, 2025 [September 9th, 2025]
- The people stood up: how war turned Iran towards everyday nationalism - The Guardian - September 9th, 2025 [September 9th, 2025]
- Iran-Contra figures Oliver North and Fawn Hall secretly marry 40 years after scandal: report - New York Post - September 9th, 2025 [September 9th, 2025]
- Irans Economic Strain and Unrest Fears Drive Khameneis Push for Narrative Control - National Council of Resistance of Iran - NCRI - September 9th, 2025 [September 9th, 2025]
- When Israel attacked Iran, it rekindled memories and sparked new dreamsfor those who'd left decades ago - Israel from the Inside with Daniel Gordis - September 9th, 2025 [September 9th, 2025]
- UN nuclear watchdog warns Iran time running out for talks on inspections - The Times of Israel - September 9th, 2025 [September 9th, 2025]
- Analysis of IAEA Iran Verification and Monitoring and NPT Safeguards Reports September 2025 - Foundation for Defense of Democracies - September 9th, 2025 [September 9th, 2025]
- Under Ayatollah Khameneis Leadership, Iran Is the Pillar of the Islamic Ummah - taghribnews.com - September 9th, 2025 [September 9th, 2025]
- Trump chides senator over Declaration of Independence analogy to Iran - - September 9th, 2025 [September 9th, 2025]
- What Aspiring Nuclear Powers Learned From Israels Strikes on Iran - IranWire - September 9th, 2025 [September 9th, 2025]
- Iran caught in nuclear standoff between Trump, Europe and Khamenei - Le Monde.fr - September 9th, 2025 [September 9th, 2025]
- Iran urges South Korea to take responsible stance on E3s illegitimate snapback move - PressTV - September 9th, 2025 [September 9th, 2025]
- Iranians Rally in Brussels Marking 60th Anniversary of the Peoples Mojahedin Organization of Iran - irannewsupdate.com - September 9th, 2025 [September 9th, 2025]
- Iran reasserts indisputable sovereignty over three Persian Gulf islands - PressTV - September 9th, 2025 [September 9th, 2025]
- Kneeling Bull: A 5,000-year-old hybrid creature from Iran with a mysterious purpose - Live Science - September 9th, 2025 [September 9th, 2025]
- Five mcm/d of Russian gas to start flowing to Iran: Iran Envoy - IranOilGas - September 9th, 2025 [September 9th, 2025]
- Iran: Resistance Units Mark MEKs 60th Anniversary with 60 Image Projections in 20 Cities - National Council of Resistance of Iran - NCRI - September 6th, 2025 [September 6th, 2025]
- UK Government Labels Iran a Persistent and Multi-Layered Threat in New Security Assessment - National Council of Resistance of Iran - NCRI - September 6th, 2025 [September 6th, 2025]
- Mideast Iran Islamic Revolution Anniversary - Martinsville Bulletin - September 6th, 2025 [September 6th, 2025]
- Louisiana congressman grateful for snapback sanctions on Iran, says they must be enforced - JNS.org - September 6th, 2025 [September 6th, 2025]
- Iran executes man over attack on security forces at 2022 Mahsa Amini protests - The Times of Israel - September 6th, 2025 [September 6th, 2025]
- Iran executes man over attack on security forces during 2022 Mahsa Amini protests - The Times of Israel - September 6th, 2025 [September 6th, 2025]
- Iran paves over mass grave of 1979 revolution victims, turning it into a parking lot - ABC News - September 6th, 2025 [September 6th, 2025]
- Tens of Thousands Rally in Brussels Marking the 60th Anniversary of the PMOI, Calling for a Free Iran - National Council of Resistance of Iran - NCRI - September 6th, 2025 [September 6th, 2025]
- 'No Business As Usual': Iran FM Rules Out Pre-war Terms For Nuclear Talks - i24NEWS - September 6th, 2025 [September 6th, 2025]
- Irans Clerical Regime Confronts Rising Fear of the PMOI and an Explosive Society - National Council of Resistance of Iran - NCRI - September 6th, 2025 [September 6th, 2025]
- Iran executes man involved in 2022 uprising over women's rights - Reuters - September 6th, 2025 [September 6th, 2025]
- Iran says calls from Japan and Australia for diplomacy hypocritical - Tehran Times - September 6th, 2025 [September 6th, 2025]
- Iran Unveils New Rural Literary Tourism Route In Kandelous, Mazandaran, Linking Local Folklore With Culture And Ecotourism, Get All The Details Here -... - September 6th, 2025 [September 6th, 2025]