Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- Live updates: Iran launches retaliatory strikes on US targets in the Middle East - CNN - June 10th, 2026 [June 10th, 2026]
- Iran and Israel Halt Exchanges of Fire - WSJ - June 10th, 2026 [June 10th, 2026]
- U.S. retaliates against Iran after American helicopter downed near Strait of Hormuz - PBS - June 10th, 2026 [June 10th, 2026]
- China May wholesale inflation hits near 4-year high on Iran war-led higher input costs, AI boom - CNBC - June 10th, 2026 [June 10th, 2026]
- Opinion | The art of no deal with Iran - The Washington Post - June 10th, 2026 [June 10th, 2026]
- U.S. launches new attacks on Iran in response to downing of helicopter, CENTCOM says - NBC News - June 10th, 2026 [June 10th, 2026]
- U.S. Finishes Strikes On Iran Made In Response To Downed Helicopter - Forbes - June 10th, 2026 [June 10th, 2026]
- What Netanyahu and Israel want out of the war with Iran - NPR - June 10th, 2026 [June 10th, 2026]
- JD Vance claims US very close to peace deal with Iran - The Guardian - June 10th, 2026 [June 10th, 2026]
- US launches strikes on Iran in retaliation for downed helicopter - The Hill - June 10th, 2026 [June 10th, 2026]
- US strikes Iran in response to helicopter shootdown - DW - June 10th, 2026 [June 10th, 2026]
- Why Lebanon may hold the key to the future of the Iran war - CNN - June 10th, 2026 [June 10th, 2026]
- US launches strikes on Iran in response to downed Army helicopter - USA Today - June 10th, 2026 [June 10th, 2026]
- Iran says ticket allocation for World Cup withdrawn days before tournament - Reuters - June 10th, 2026 [June 10th, 2026]
- NYT: Iran will dilute rather than hand over uranium stockpile as part of deal with US - The Times of Israel - June 10th, 2026 [June 10th, 2026]
- U.S. and Iran Zero In on Four Nuclear Issues in Talks - The New York Times - June 10th, 2026 [June 10th, 2026]
- Israel and Iran trade strikes, imperiling already fragile ceasefire in war's 100th day - CBS News - June 10th, 2026 [June 10th, 2026]
- Trump vows to respond after Iran downed a U.S. Army helicopter near Strait of Hormuz - NPR - June 10th, 2026 [June 10th, 2026]
- Trump invokes The West Wing in apparent justification of latest Iran strikes - The Washington Post - June 10th, 2026 [June 10th, 2026]
- Iran and Israel say attacks halted after Trump tells both to "stop 'shooting'" on war's 101st day - CBS News - June 10th, 2026 [June 10th, 2026]
- The U.S. Strikes Iran After Trump Vowed to Retaliate - The New York Times - June 10th, 2026 [June 10th, 2026]
- Trump keeps forecasting an Iran deal why the White House still thinks it can happen - Fox News - June 10th, 2026 [June 10th, 2026]
- We Need a Long-Term Strategy to Deal With Iran - The Dispatch - June 10th, 2026 [June 10th, 2026]
- Has the ceasefire really survived the latest US-Iran tensions? - The Jerusalem Post - June 10th, 2026 [June 10th, 2026]
- Iran targets US bases in Jordan and the Gulf after Trump orders strikes near Hormuz - Al-Monitor - June 10th, 2026 [June 10th, 2026]
- Iran says US has revoked World Cup ticket allocation for their supporters - Al Jazeera - June 10th, 2026 [June 10th, 2026]
- U.S. and Iran Move Toward Agreement to Reopen the Strait of Hormuz - The New York Times - May 29th, 2026 [May 29th, 2026]
- Iran, Israel, and the US: When governments lose the language of diplomacy, war follows - Jurist.org - May 29th, 2026 [May 29th, 2026]
- Iran War Updates: U.S. Officials Say They Are Closing In on Arrangement to Reopen Strait of Hormuz - The New York Times - May 29th, 2026 [May 29th, 2026]
- NJ Sen. Cory Booker raises alarm on Delaney Hall, talks Iran, taxing the rich, and a new New Deal in extended interview - ABC7 Eyewitness News - May 29th, 2026 [May 29th, 2026]
- Are US and Iran close to peace or sliding back to war? - BBC - May 29th, 2026 [May 29th, 2026]
- What Iran Stands to Gain From a Truce Deal With the United States - Foreign Policy - May 29th, 2026 [May 29th, 2026]
- Iran threats expose the aging fleet that repairs undersea Internet cables - Scientific American - May 27th, 2026 [May 27th, 2026]
- Trump gathers Cabinet as he looks to seal deal to end war that some backers worry will embolden Iran - AP News - May 27th, 2026 [May 27th, 2026]
- Iran war splits global markets into clear winners and losers - Reuters - May 27th, 2026 [May 27th, 2026]
- Warning To Trump: Negotiating With Iran Is A Fools Errand - Forbes - May 27th, 2026 [May 27th, 2026]
- Trump moves Camp David cabinet meeting to White House as Iran talks continue - The Guardian - May 27th, 2026 [May 27th, 2026]
- Giving Iran control of Strait of Hormuz would be a mistake, Bolton argues - PBS - May 27th, 2026 [May 27th, 2026]
- What we know and dont know about the possible deal to end the Iran war - AP News - May 27th, 2026 [May 27th, 2026]
- Iran may consider transferring its uranium to China - The Jerusalem Post - May 27th, 2026 [May 27th, 2026]
- Trump to hold Cabinet meeting amid declining approval on Iran, economy - The Washington Post - May 27th, 2026 [May 27th, 2026]
- Iran condemns US strikes as a show of 'bad faith' and begins restoring internet after long shutdown - AP News - May 27th, 2026 [May 27th, 2026]
- Trump might not have a good way out of the Iran war - CNN - May 27th, 2026 [May 27th, 2026]
- Iran threatens retaliation after U.S. strikes in southern Iran - The Washington Post - May 27th, 2026 [May 27th, 2026]
- Iran Revolutionary Guards official: Low possibility of renewed war due to 'enemy's weakness' - The Times of Israel - May 27th, 2026 [May 27th, 2026]
- When Iran thumbs its nose at the ceasefire, the Trump administration shrugs - CNN - May 27th, 2026 [May 27th, 2026]
- Makes no sense: experts doubt pause in US arms sale to Taiwan is due to Iran war - The Guardian - May 27th, 2026 [May 27th, 2026]
- U.S. and Iran suggest progress on peace talks, but deal not imminent - PBS - May 27th, 2026 [May 27th, 2026]
- Oil Prices Fall as Uneasy Truce Holds Between U.S. and Iran - The New York Times - May 27th, 2026 [May 27th, 2026]
- Trump to meet with top advisors as Iran accuses U.S. of violating ceasefire - CBS News - May 27th, 2026 [May 27th, 2026]
- US strikes Iran again: What we know, and is the ceasefire over? - Al Jazeera - May 27th, 2026 [May 27th, 2026]
- U.S. Carries Out Renewed Strikes in Southern Iran - The New York Times - May 27th, 2026 [May 27th, 2026]
- These Are 5 of the Main Issues to Be Resolved in an Iran-U.S. Peace Deal - The New York Times - May 27th, 2026 [May 27th, 2026]
- Here's what the draft memo for a proposed deal with Iran includes - CBS News - May 27th, 2026 [May 27th, 2026]
- Former MK warns Iran war will damage Israel-US ties long-term - The Jerusalem Post - May 27th, 2026 [May 27th, 2026]
- The Iran War Is Crippling One of the Worlds Wealthiest Nations - The New York Times - May 17th, 2026 [May 17th, 2026]
- Rupee seen testing record lows; bonds to extend fall on Iran war jitters - Reuters - May 17th, 2026 [May 17th, 2026]
- Netanyahu 'blunder' threatens US-backed Israel-UAE alliance at critical moment with Iran: analyst - Fox News - May 17th, 2026 [May 17th, 2026]
- Wont be anything left: Trump issues warning to Iran after national security team meeting - CNN - May 17th, 2026 [May 17th, 2026]
- Drone strikes UAE nuclear plant as US and Iran signal they are prepared to resume war - AP News - May 17th, 2026 [May 17th, 2026]
- Trump warns Iran that 'there won't be anything left of them' without peace deal - France 24 - May 17th, 2026 [May 17th, 2026]
- 'This may be the last time you hear my voice': Political executions surge in Iran since start of war - BBC - May 17th, 2026 [May 17th, 2026]
- Clock is ticking for Iran to accept a deal, Trump warns - The Times - May 17th, 2026 [May 17th, 2026]
- Trump warns Iran clock is ticking as peace negotiations stall - The Hill - May 17th, 2026 [May 17th, 2026]
- President Trump Warns Iran Time Is of the Essence After Netanyahu Call - The Media Line - May 17th, 2026 [May 17th, 2026]
- Iran latest: Trump warns Iran that "the clock is ticking" in new social media post - LiveNOW from FOX - May 17th, 2026 [May 17th, 2026]
- Trump, Netanyahu to speak Sunday amid reports of potential revival of military action on Iran - Fox News - May 17th, 2026 [May 17th, 2026]
- Iran set to play 2026 World Cup after 'positive meeting' with FIFA - USA Today - May 17th, 2026 [May 17th, 2026]
- Crypto Analysts Brace for Risk-Off Monday Open as Trump Teases Iran Nuclear Strike - Yahoo Finance - May 17th, 2026 [May 17th, 2026]
- Lindsey Graham says the U.S. has hit a wall on Iran negotiations: Full interview - NBC News - May 17th, 2026 [May 17th, 2026]
- Sen. Graham: I would give up my job to disarm Iran - NBC News - May 17th, 2026 [May 17th, 2026]
- Israel built two covert military bases in Iraq to support Iran strikes report - The Times of Israel - May 17th, 2026 [May 17th, 2026]
- Lindsey Graham Says U.S. Negotiations With Iran Have Hit a Wall - News of the United States - NOTUS - May 17th, 2026 [May 17th, 2026]
- Iran Has Found Another Achilles' Heel Lurking Beneath Strait Of Hormuz - NDTV - May 17th, 2026 [May 17th, 2026]
- Fears Grow That Iran May Be Using Proxy Groups Beyond Mideast - The New York Times - May 17th, 2026 [May 17th, 2026]
- Markets jittery as oil crisis bleeds into debt selloff, while Trump weighs military options on Iran - Fortune - May 17th, 2026 [May 17th, 2026]
- Iran eyes a new source of power deep beneath the Strait of Hormuz - CNN - May 17th, 2026 [May 17th, 2026]
- Netanyahu speaks with Trump about Iran war ahead of limited security meeting - The Times of Israel - May 17th, 2026 [May 17th, 2026]
- "Won't Be Anything Left Of Them": Trump's "Clock Ticking" Warning To Iran - NDTV - May 17th, 2026 [May 17th, 2026]
- As Iran talks stall, Israel and US prepping to renew war as soon as next week report - The Times of Israel - May 17th, 2026 [May 17th, 2026]