Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- Israel and Iran exchange strikes as Trump says U.S. is negotiating end to war - The Washington Post - March 24th, 2026 [March 24th, 2026]
- What the Iran War Reveals About the Limits of US Power - Geopolitical Monitor - March 24th, 2026 [March 24th, 2026]
- Iran foreign minister signaled readiness for deal in call with US - Ynet - - March 24th, 2026 [March 24th, 2026]
- Opinion | How Bad Could the Iran Oil Crisis Get? - The New York Times - March 24th, 2026 [March 24th, 2026]
- What to understand why Trump is still bombing Iran? Look to Nixon and Vietnam | Kenneth Roth - The Guardian - March 24th, 2026 [March 24th, 2026]
- What we know on Day 25 of the US and Israels war with Iran - CNN - March 24th, 2026 [March 24th, 2026]
- Opinion | Theres reason to be skeptical of Trumps productive talks with Iran - MS NOW - March 24th, 2026 [March 24th, 2026]
- As War in Iran Disrupts Air Travel, Heres Where Its Hitting Hardest - The New York Times - March 24th, 2026 [March 24th, 2026]
- Middle East violence continues after Trump claims very good talks with Iran - The Guardian - March 24th, 2026 [March 24th, 2026]
- Qatar is not directly mediating between US and Iran, ministry spokesperson says - Reuters - March 24th, 2026 [March 24th, 2026]
- Will Iran Turn to Terrorism? - Foreign Affairs - March 24th, 2026 [March 24th, 2026]
- Trump searches for an exit strategy in Iran as $100 oil looms over the midterms - Fortune - March 24th, 2026 [March 24th, 2026]
- Trump Delays Threat to Iran, but War Negotiations Are in Early Stage - The New York Times - March 24th, 2026 [March 24th, 2026]
- 82nd Airborne considered for Iran deployment as Marines move into position, report says - Stars and Stripes - March 24th, 2026 [March 24th, 2026]
- Amazon faces further AWS disruption in the Middle East from Iran conflict - CNBC - March 24th, 2026 [March 24th, 2026]
- Netanyahu vows further strikes on Iran and Lebanon as missile hits Tel Aviv - The Guardian - March 24th, 2026 [March 24th, 2026]
- Trump says Iran is eager for a deal to end the war as he extends deadline to allow for diplomacy - AP News - March 24th, 2026 [March 24th, 2026]
- Gold Has Been a Terrible Iran War Hedge -- Why? - Bloomberg.com - March 24th, 2026 [March 24th, 2026]
- Trumps claim that US and Iran are talking elicits market cheers and plenty of skepticism - AP News - March 24th, 2026 [March 24th, 2026]
- Iran Is Trying to Defeat America in the Living Room - The Atlantic - March 24th, 2026 [March 24th, 2026]
- Ultimatums, diplomacy and a trip to Graceland as Trump eyes a deal with Iran - BBC - March 24th, 2026 [March 24th, 2026]
- Iran war takes mounting toll on Americas military - The Hill - March 24th, 2026 [March 24th, 2026]
- Iran denies any talks with US after Trump claims productive discussions - Al Jazeera - March 24th, 2026 [March 24th, 2026]
- Trump says U.S. is postponing some strikes as it negotiates end to war with Iran - The Washington Post - March 24th, 2026 [March 24th, 2026]
- JD Vance role touted as Pakistan attempts to broker US-Iran peace talks - The Guardian - March 24th, 2026 [March 24th, 2026]
- A Mysterious Numbers Station Is Broadcasting Through the Iran War - WIRED - March 24th, 2026 [March 24th, 2026]
- How North Koreas Kim Jong-un Is Using the Iran War to Justify His Nuclear Arsenal - The New York Times - March 24th, 2026 [March 24th, 2026]
- Saudis and UAE Take Steps Toward Joining Iran War, WSJ Reports - Bloomberg.com - March 24th, 2026 [March 24th, 2026]
- Iran attacks in Strait of Hormuz are economic terrorism against every nation, UAE oil CEO says - CNBC - March 24th, 2026 [March 24th, 2026]
- Why Trump may not be able to TACO in Iran even if he wants to - CNN - March 24th, 2026 [March 24th, 2026]
- Five problems the Iran war could solve for Israels Netanyahu - Al Jazeera - March 20th, 2026 [March 20th, 2026]
- What we know on the 21st day of the US and Israels war with Iran - CNN - March 20th, 2026 [March 20th, 2026]
- Deepening Iran conflict exposes cracks in U.S. and Israeli objectives - The Washington Post - March 20th, 2026 [March 20th, 2026]
- Iran war creates growing cracks within Trump's MAGA movement - PBS - March 20th, 2026 [March 20th, 2026]
- Japan wanted inflation and Iran war could grant that wish. But it's not the type Tokyo desires - CNBC - March 20th, 2026 [March 20th, 2026]
- Trump Says He Wont Send Troops to Iran but Leaves Wiggle Room - The New York Times - March 20th, 2026 [March 20th, 2026]
- The Iran war is sending shockwaves through the world's busiest IPO market - CNBC - March 20th, 2026 [March 20th, 2026]
- How the Iran War Narrowed Flight Corridors Between Europe and Asia - The New York Times - March 20th, 2026 [March 20th, 2026]
- Russia, China and the US the global winners and losers of the Iran war - BBC - March 20th, 2026 [March 20th, 2026]
- Trump caught unprepared by escalation of war with Iran - Le Monde.fr - March 20th, 2026 [March 20th, 2026]
- The Memo: Frustrated Trump struggles against perception that hes losing control of Iran war - The Hill - March 20th, 2026 [March 20th, 2026]
- Unpacking Netanyahus latest claims about the war on Iran - Al Jazeera - March 20th, 2026 [March 20th, 2026]
- Iran retaliation is forcing Gulf nations into a stark decision: whether to join the fight - NBC News - March 20th, 2026 [March 20th, 2026]
- Are US and Israel in lockstep in Iran war? Deciphering Trump's post after gas field attacks - BBC - March 20th, 2026 [March 20th, 2026]
- Iran War Fallout: Southeast Asia Hard Hit by Skyrocketing Fuel Prices - The New York Times - March 20th, 2026 [March 20th, 2026]
- Netanyahu says Iran is being 'decimated' but revolution requires 'ground component' - CNBC - March 20th, 2026 [March 20th, 2026]
- Newspaper headlines: Iran war unleashes 'world energy shock' and 'King of the coast' - BBC - March 20th, 2026 [March 20th, 2026]
- $200 billion for the war in Iran? Trump calls it a 'small price to pay.' - Yahoo Finance - March 20th, 2026 [March 20th, 2026]
- Iran Leaves an Isolated Trump Grappling With Historic Oil Crisis - Bloomberg.com - March 20th, 2026 [March 20th, 2026]
- Iran soccer chief: We'll boycott U.S., but not the World Cup - ESPN - March 20th, 2026 [March 20th, 2026]
- Trump and Iran Dominate the Agenda as Europes Leaders Meet. Here Are 4 Things to Know. - The New York Times - March 20th, 2026 [March 20th, 2026]
- The Guardian view on the Iran war escalation: as Trump breaks things, who will pick up the pieces? | Editorial - The Guardian - March 20th, 2026 [March 20th, 2026]
- Father of service member killed in Iran war said he never told Pete Hegseth to 'finish' the job - NBC News - March 20th, 2026 [March 20th, 2026]
- Trump mulls Kharg Island takeover to force Iran to open Hormuz Strait, Axios reports - Reuters - March 20th, 2026 [March 20th, 2026]
- Iran womens football team feted in Tehran after asylum battle at Asian Cup - Al Jazeera - March 20th, 2026 [March 20th, 2026]
- The Latest: Iran's Revolutionary Guard says Tehran still building missiles and the war will go on - NBC4 Washington - March 20th, 2026 [March 20th, 2026]
- Opinion | After the Iran war, the global economy will never be the same - The Washington Post - March 20th, 2026 [March 20th, 2026]
- Detained Britons used as 'human shields' in Iran war zone, family says - Reuters - March 20th, 2026 [March 20th, 2026]
- Teenager among first to be executed over Iran's anti-government protests - BBC - March 20th, 2026 [March 20th, 2026]
- Trump references Pearl Harbor during meeting with Japanese PM on Iran war - Al Jazeera - March 20th, 2026 [March 20th, 2026]
- How people are making millions on the Iran war - Vox - March 18th, 2026 [March 18th, 2026]
- Iran live updates: Gabbard dodges question on 'imminent threat' in Senate hearing, Iranian intelligence minister killed - MS NOW - March 18th, 2026 [March 18th, 2026]
- This Emirati billionaire put a voice to Gulf anger over Trumps war in Iran - The Washington Post - March 18th, 2026 [March 18th, 2026]
- Trump's failed strong-arming of allies on Iran shows that pressure is losing its effect - PBS - March 18th, 2026 [March 18th, 2026]
- Airstrikes Pound Middle East as Iran Conflict Approaches Third Week - The New York Times - March 18th, 2026 [March 18th, 2026]
- The Iran Wars Next Threat Is to Food and Water - The Atlantic - March 18th, 2026 [March 18th, 2026]
- Iran confirms the death of its intelligence chief, 3rd top official killed in 24 hours - NPR - March 18th, 2026 [March 18th, 2026]
- Netanyahu Hopes Strikes on Iran Will Lead to Uprising and Regime Change - The New York Times - March 18th, 2026 [March 18th, 2026]
- Live updates: Gabbard declines to say if Trump was warned on Iran - NewsNation - March 18th, 2026 [March 18th, 2026]
- 'Very difficult to stop': BBC visits scene of Iran cluster bomb strike on Israel - BBC - March 18th, 2026 [March 18th, 2026]
- Vance, Wright to address oil execs amid Iran tensions - Politico - March 18th, 2026 [March 18th, 2026]
- Bolton says he briefed Trump on Iran scenarios: Hard to believe that he forgot - The Hill - March 18th, 2026 [March 18th, 2026]
- Iran confirms killing of intel minister in third assassination in two days - Al Jazeera - March 18th, 2026 [March 18th, 2026]
- Ossoff grills Gabbard on whether Iran posed imminent nuclear threat - The Hill - March 18th, 2026 [March 18th, 2026]
- What we know on the 19th day of the US and Israels war with Iran - CNN - March 18th, 2026 [March 18th, 2026]
- Takeaways from intelligence officials testimony amid war with Iran - CNN - March 18th, 2026 [March 18th, 2026]
- Trump confirms meeting with Chinas Xi Jinping delayed as war on Iran rages - Al Jazeera - March 18th, 2026 [March 18th, 2026]
- Tulsi Gabbard and Top Intelligence Officials Will Testify on Iran War in Senate Hearing - The New York Times - March 18th, 2026 [March 18th, 2026]
- How the Iran war is weakening Donald Trump - The Economist - March 18th, 2026 [March 18th, 2026]
- For U.S., Unmet Expectations in Iran Fit a Familiar Pattern in the Region - The New York Times - March 18th, 2026 [March 18th, 2026]