Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- U.S. negotiating position on Iran in flux as talks continue - The Washington Post - April 25th, 2025 [April 25th, 2025]
- Trump wants Iran deal but will be "leading the pack" for war without one - Axios - April 25th, 2025 [April 25th, 2025]
- Negotiations between Iran and the US over Tehran's nuclear program return to secluded Oman - AP News - April 25th, 2025 [April 25th, 2025]
- Congratulations to Paraguay for Confronting Iran and its Proxies - U.S. Department of State (.gov) - April 25th, 2025 [April 25th, 2025]
- 'Waste That St': In Interview With Free Beacon, Fetterman Tells Trump To Dump Iran Talks and Destroy Tehran's Nuclear Facilities - freebeacon.com - April 25th, 2025 [April 25th, 2025]
- Iran rejects demand from US to rely on imported uranium - The Guardian - April 25th, 2025 [April 25th, 2025]
- Israel said to fear US moving fast toward bad deal that wont block Iran from nukes - The Times of Israel - April 25th, 2025 [April 25th, 2025]
- Iran fortifying buried nuclear sites as talks with US continue, report says - Reuters - April 25th, 2025 [April 25th, 2025]
- Iran, France signal readiness for nuclear talks amid US negotiations - Reuters - April 25th, 2025 [April 25th, 2025]
- Rubio says Iran must give up nuclear enrichment in any deal with the US - AP News - April 25th, 2025 [April 25th, 2025]
- The US, Iran and the bomb - Al Jazeera - April 25th, 2025 [April 25th, 2025]
- What do 'expert level' talks signal for the progress of Iran-U.S. nuclear negotiations? - NBC News - April 25th, 2025 [April 25th, 2025]
- Act of negotiating with Iran is 'problematic,' rocket scientist says - Fox Business - April 25th, 2025 [April 25th, 2025]
- What do expert level talks signal for the progress of the Iran-US nuclear negotiations? - AP News - April 25th, 2025 [April 25th, 2025]
- U.S. Offers Iran Civilian Nuclear Program in Possible Compromise With Tehran - WSJ - April 25th, 2025 [April 25th, 2025]
- As Iran fortifies nuke sites, US says it can have civilian nuclear program if no enrichment - The Times of Israel - April 25th, 2025 [April 25th, 2025]
- Iran weighs pace of nuclear talks with US, unsure if to push for deal with Trump - analysis - The Jerusalem Post - April 25th, 2025 [April 25th, 2025]
- Iran's FM Araghchi to head to Oman for nuclear talks with US - The New Arab - April 25th, 2025 [April 25th, 2025]
- UN watchdog asks Iran to clarify tunnels but upbeat on deal - France 24 - April 25th, 2025 [April 25th, 2025]
- Trump: Willing to meet Leader Khamenei as Iran talks advance - Shafaq News - - April 25th, 2025 [April 25th, 2025]
- Rubio says war with Iran would be much messier than what people are used to seeing - The Hill - April 25th, 2025 [April 25th, 2025]
- After blows to proxies, Iran advances huge space program with Russian assistance - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- Everything you need to know about Iran-US nuclear negotiations - Al Jazeera - April 21st, 2025 [April 21st, 2025]
- Source close to White House: US-Iran talks expected to collapse - www.israelhayom.com - April 21st, 2025 [April 21st, 2025]
- Iran-US talks over Tehrans nuclear program hinge on a billionaire and a seasoned diplomat - AP News - April 21st, 2025 [April 21st, 2025]
- Iran, US task experts with framework for a nuclear deal after 'progress' in talks - Reuters - April 21st, 2025 [April 21st, 2025]
- US and Iran say talks over Tehrans nuclear program make progress and set plans for more - AP News - April 21st, 2025 [April 21st, 2025]
- Trump cant afford to simply revive Obamas Iran nuclear deal - Atlantic Council - April 21st, 2025 [April 21st, 2025]
- What to know about the tensions between Iran and the US before their second round of talks - AP News - April 21st, 2025 [April 21st, 2025]
- In Iran Talks, Trump Is Edging Toward Reviving an Old Deal - The New York Times - April 21st, 2025 [April 21st, 2025]
- Iran, US report progress in nuclear talks, confirm third round next week - Al Jazeera - April 21st, 2025 [April 21st, 2025]
- Iran Says Talks With U.S. to Continue After Positive Meeting - WSJ - WSJ - April 21st, 2025 [April 21st, 2025]
- Iran says nuclear deal is possible if Washington is realistic - Reuters - April 21st, 2025 [April 21st, 2025]
- After Rome talks, Tehran says Iran and US to start designing framework for nuclear deal - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- Trump Is About to Learn That Iran Is a Problem Without a Solution - Foreign Policy - April 21st, 2025 [April 21st, 2025]
- Hopes for Iran nuclear talks tempered by threats and mixed messages - BBC - April 21st, 2025 [April 21st, 2025]
- With his promises of peace unmet in Gaza and Ukraine, Trump may find Iran just as tough - Reuters - April 21st, 2025 [April 21st, 2025]
- Second round of US-Iran nuclear talks end, third round set for next week - France 24 - April 21st, 2025 [April 21st, 2025]
- U.S., Iran officials project progress in second round of nuclear talks - The Washington Post - April 21st, 2025 [April 21st, 2025]
- Iran offered US a nuclear agreement with same enrichment cap as 2015 deal report - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- As Iran talks resume, White House fends off bombing hawks - The Washington Post - April 21st, 2025 [April 21st, 2025]
- Trump says he is in no rush to attack Iran over nuclear program - Reuters - April 21st, 2025 [April 21st, 2025]
- US-Iran: future stability of Middle East hangs on success of nuclear deal but initial signs are not good - The Conversation - April 21st, 2025 [April 21st, 2025]
- Omans sultan to meet Putin in Moscow after Iran-US nuclear talks mediated by Muscat - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- Israel said to still eye limited attack on Iran nuclear sites despite Trump waving off plan - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- Netanyahu: We will not surrender to Hamas, Iran won't have a nuclear weapon - The Jerusalem Post - April 21st, 2025 [April 21st, 2025]
- US and Iran agree to another round of talks to end nuclear stand-off - Financial Times - April 21st, 2025 [April 21st, 2025]
- Mossad chief, Dermer meet US envoy Witkoff in Paris ahead of US-Iran nuclear talks - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- Iran and US move to expert-level talks after 'good meeting' in Rome - Middle East Eye - April 21st, 2025 [April 21st, 2025]
- April 19: US official: Very good progress made in Iran talks; well meet again next week - The Times of Israel - April 21st, 2025 [April 21st, 2025]
- Iran confirms that the 2nd round of nuclear talks with the US will be in Rome - AP News - April 18th, 2025 [April 18th, 2025]
- Iran's Khamenei sends letter to Putin ahead of talks with US - Reuters - April 18th, 2025 [April 18th, 2025]
- Saudi defence minister arrives in Tehran ahead of Iran-US talks - Reuters - April 18th, 2025 [April 18th, 2025]
- Iran Says Despite Shifting U.S. Messages, It Plans to Keep Participating in Nuclear Talks - The New York Times - April 18th, 2025 [April 18th, 2025]
- Opinion | Its a Mistake to Think the Biggest Problem With Iran Is Nuclear Weapons - The New York Times - April 18th, 2025 [April 18th, 2025]
- Mike Pompeo: We Dont Need a Fake Deal with Iran - The Free Press - April 18th, 2025 [April 18th, 2025]
- Ahead of 2nd round of nuclear negotiations, U.S. and Iran harden positions - PBS - April 18th, 2025 [April 18th, 2025]
- US, Iran Set for Second Round of Nuclear Talks as Iranian FM Warns Against Unrealistic Demands - Algemeiner.com - April 18th, 2025 [April 18th, 2025]
- Trump team's Iran divide: Dialogue vs. detonation to end nuclear threat - Axios - April 18th, 2025 [April 18th, 2025]
- Iran says its right to uranium enrichment is non-negotiable - Reuters - April 18th, 2025 [April 18th, 2025]
- Iran confirms next round of nuclear talks with US set for Rome on Saturday - Al Jazeera - April 18th, 2025 [April 18th, 2025]
- Oil posts weekly gain on trade deal hopes, new Iran sanctions - Reuters - April 18th, 2025 [April 18th, 2025]
- Trump Warns Iran: A Nuclear Iran Will Never Bring Happiness to Its People - kurdistan24.net - April 18th, 2025 [April 18th, 2025]
- Scoop: Trump holds situation room meeting on Iran nuclear deal negotiations - Axios - April 18th, 2025 [April 18th, 2025]
- Why Iran Doesnt Need the Bomb - The National Interest - April 18th, 2025 [April 18th, 2025]
- Iran's folded rocks: The crumpled mountains at the intersection of Asia and Europe - Live Science - April 18th, 2025 [April 18th, 2025]
- IAEA chief on Tehran visit: Iran, US dont have much time to reach nuclear deal - The Times of Israel - April 18th, 2025 [April 18th, 2025]
- Trump Gives Conflicting Signals and Mixed Messages on Iran Nuclear Talks - The New York Times - April 18th, 2025 [April 18th, 2025]
- Trump holds Situation Room meeting on Iran, officials say - Reuters - April 18th, 2025 [April 18th, 2025]
- Trump warns Iran it can thrive and be a great country without death - Cleveland.com - April 18th, 2025 [April 18th, 2025]
- Another US aircraft carrier in Mideast waters ahead of second round of Iran-US nuclear talks - AP News - April 18th, 2025 [April 18th, 2025]
- Trump blocked Israeli-proposed joint attack on Iran to pursue nuclear deal report - The Times of Israel - April 18th, 2025 [April 18th, 2025]
- If US and Iran Clash, This Remote Base Could Be First To Fight - Newsweek - April 18th, 2025 [April 18th, 2025]
- Trump Trashed the Iran Nuclear Deal. Will His Be Any Better? - The New York Times - April 18th, 2025 [April 18th, 2025]
- Iran wants to drag out talks, Trump wants a deal now. Neither is good for Israel - The Times of Israel - April 18th, 2025 [April 18th, 2025]
- Rubio blames Iran for JCPOA collapse, overlooks U.S. withdrawal from the deal - Tehran Times - April 18th, 2025 [April 18th, 2025]
- Iran seeks Russia's support for its nuclear talks with US - theheraldreview.com - April 18th, 2025 [April 18th, 2025]
- Iran believes it can reach nuclear agreement with US, wants Russia to play role - The Times of Israel - April 18th, 2025 [April 18th, 2025]
- Iran wants guarantees Trump will not quit a new nuclear pact, official says - The Times of Israel - April 18th, 2025 [April 18th, 2025]
- US-Iran talks to be held in Rome following confusion over location - Euronews.com - April 18th, 2025 [April 18th, 2025]