Iran-based hackers targeting nuclear security experts through Mac … – The Record from Recorded Future News
Hackers supporting the government of Iran are targeting experts in Middle Eastern affairs and nuclear security in a new campaign that researchers said involved malware for both Apple and Microsoft products.
Cybersecurity experts from Proofpoint attributed the campaign to a group they call TA453 but also is known as Charming Kitten, Mint Sandstorm or APT42, which has previously been tied to the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
They found hackers pretending to be a senior fellow with the U.K. think tank the Royal United Services Institute (RUSI) while attempting to spread malware to a nuclear security expert at a U.S.-based think tank focused on foreign affairs.
The hackers continue to adapt the tools used during their attacks, deploying novel file types and targeting new operating systems, specifically sending Mac malware to one of its recent targets, Proofpoint said.
TA453s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats, said Joshua Miller, a senior threat researcher for the company.
The threat actors continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community informed defense is to frustrate even the most advanced adversaries.
In a report published Thursday, Miller and other Proofpoint researchers explained that the group uses Google Scripts, Dropbox and CleverApps to disrupt the efforts of threat hunters.
The goal of the campaign is reconnaissance, with the hackers deploying several backdoors in victims systems to gather intelligence.
The hackers were forced to shift their tactics in May after Microsoft made changes last year to a popular feature in its Office suite of apps. Past campaigns analyzed by Proofpoint saw the hackers use Microsofts Visual Basic for Applications (VBA) macro to deploy malware but the tech giant announced that it is now blocking the feature by default in a variety of Office apps to limit its use among hackers.
Proofpoint attributed the campaign to Iranian actors based on both direct code similarities and similarities in overall campaign tactics, techniques, and procedures. Two of the backdoors found in the campaign date back to ones seen in 2021.
The campaign began in May with an email to an expert from a hacker purporting to be a senior fellow with RUSI.
The email said the researchers were working on a project called Iran in the Global Security Context and were looking for feedback from experts. To bolster its legitimacy, the hackers said the project was being worked on by other well-known nuclear security experts. The attackers had previously sent emails masquerading as those people, too. The hackers even offered to pay the expert for their take on the document.
TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho, the researchers said.
At one point the hackers realized that a malicious file would not run on the victims Apple computer, so they sent another email with malware that would work on Mac operating systems.
Proofpoint said the likely goal is monitoring experts who are likely playing some role in the foreign policy positions taken by governments involved in the Joint Comprehensive Plan of Action (JCPOA) negotiations, known colloquially as the Iran nuclear agreement.
Proofpoint noted that its investigation into the campaign was assisted by Dropbox and HSBC Cyber Intelligence and Threat Analysis. Dropbox removed the accounts that were associated with the campaign after being notified by Proofpoint.
In April, Charming Kitten was accused of deploying a new strain of malware named BellaCiao against several victims in the U.S., Europe, India, Turkey and other countries.
Microsoft reported earlier this year that the same Iranian hacking group spent much of 2021 and 2022 directly targeting US critical infrastructure including seaports, energy companies, transit systems, and a major US utility and gas entity.
The increased aggression of Iranian threat actors appeared to correlate with other moves by the Iranian regime under a new national security apparatus, suggesting such groups are less bounded in their operations, Microsoft explained.
Recorded Future
Intelligence Cloud.
Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See original here:
Iran-based hackers targeting nuclear security experts through Mac ... - The Record from Recorded Future News
- The violence in Iran could lead to civil war - The Economist - February 2nd, 2026 [February 2nd, 2026]
- U.S. and Iran plan talks in Istanbul, as Trump warns of bad things - The Washington Post - February 2nd, 2026 [February 2nd, 2026]
- Trump says talks with Iran ongoing - Reuters - February 2nd, 2026 [February 2nd, 2026]
- Trump pairs deal talk with war threats ahead of Iran negotiations - - February 2nd, 2026 [February 2nd, 2026]
- As US and Iran set for talks, Trump warns bad things will happen if no deal reached - The Times of Israel - February 2nd, 2026 [February 2nd, 2026]
- U.S. and Iran may hold talks in Istanbul on Friday as Trump weighs military action - NBC News - February 2nd, 2026 [February 2nd, 2026]
- Iran summons EU ambassadors to protest Revolutionary Guard being listed as a terror group - ABC News - February 2nd, 2026 [February 2nd, 2026]
- Oscar-Nominated Screenwriter Arrested in Iran for Criticizing Regime - The New York Times - February 2nd, 2026 [February 2nd, 2026]
- U.S. and Iran expected to hold nuclear talks on Friday, sources say - NBC News - February 2nd, 2026 [February 2nd, 2026]
- Iran rebuilds nuclear sites as US weighs strike - The Jerusalem Post - February 2nd, 2026 [February 2nd, 2026]
- Trump says big ships are heading to Iran right now in new threat - latest - The Independent - February 2nd, 2026 [February 2nd, 2026]
- Co-writer of Oscar-nominated film It Was Just an Accident arrested in Iran - The Guardian - February 2nd, 2026 [February 2nd, 2026]
- Ahead of Friday nuclear talks with Iran, Witkoff heading to Israel to meet PM, Zamir - The Times of Israel - February 2nd, 2026 [February 2nd, 2026]
- Israel to push for US to demand that Iran give up nuclear program, missiles, proxies report - The Times of Israel - February 2nd, 2026 [February 2nd, 2026]
- Iran has repeatedly proved itself untrustworthy in negotiations: Brit Hume - Fox News - February 2nd, 2026 [February 2nd, 2026]
- U.S. tells Iran it is ready to meet and negotiate a deal - Axios - February 2nd, 2026 [February 2nd, 2026]
- Voices from inside Iran : State of the World from NPR - NPR - February 2nd, 2026 [February 2nd, 2026]
- US, Iran signal talks to avert military conflict amid tensions in the Gulf - Al Jazeera - February 2nd, 2026 [February 2nd, 2026]
- Trump weighs diplomacy with Iran amid rising tensions - Fox News - February 2nd, 2026 [February 2nd, 2026]
- Alarm grows over detention of doctors who treated Iran protesters - - February 2nd, 2026 [February 2nd, 2026]
- Interview with the Director of Iranian Studies: How the West Gets Iran Wrong - The Stanford Review - February 2nd, 2026 [February 2nd, 2026]
- Talks Are Iran's Last Chance to Avoid Confrontation With Trump but Wide Gaps Remain - Haaretz - February 2nd, 2026 [February 2nd, 2026]
- Iran's foreign minister says Tehran ready to resume nuclear talks with U.S. - Axios - February 2nd, 2026 [February 2nd, 2026]
- Iran heads for make or break this week over averting war with US - Sky News - February 2nd, 2026 [February 2nd, 2026]
- US, Iran ready to talk, with mediators organizing meeting in Ankara report - The Times of Israel - February 2nd, 2026 [February 2nd, 2026]
- Iran and U.S. to hold nuclear talks on Friday as Trump warns Tehran - The Japan Times - February 2nd, 2026 [February 2nd, 2026]
- Trump tells Iran to drop nuclear aims and stop killing protesters to avoid military action - BBC - February 2nd, 2026 [February 2nd, 2026]
- Iran orders talks with US as Trump warns of 'bad things' if no deal reached - The Mountaineer - February 2nd, 2026 [February 2nd, 2026]
- The War Room newsletter: Three ways Donald Trump could strike Iran - The Economist - January 26th, 2026 [January 26th, 2026]
- Aircraft carrier reaches Middle East, bolstering Iran options for Trump - The Washington Post - January 26th, 2026 [January 26th, 2026]
- Iran Protest Death Toll Could Top 30,000, According to Local Health Officials - Time Magazine - January 26th, 2026 [January 26th, 2026]
- Iran offline: How a government can turn off the internet : Short Wave - NPR - January 26th, 2026 [January 26th, 2026]
- Lebanon's Hezbollah chief says group concerned with confronting US threat against Iran - Reuters - January 26th, 2026 [January 26th, 2026]
- New Iran videos show bodies piled in hospital and snipers on roofs - BBC - January 26th, 2026 [January 26th, 2026]
- US Official says Washington is open for business if Iran wishes to contact them - Reuters - January 26th, 2026 [January 26th, 2026]
- Trump warned off Iran strikes in 'you will reap the whirlwind' threat - Sky News - January 26th, 2026 [January 26th, 2026]
- Airlines Are Suspending Flights to Dubai, Iran, and IsraelHere's What to Know - Cond Nast Traveler - January 26th, 2026 [January 26th, 2026]
- Pools of blood, hundreds of gunshots: I am a surgeon in Iran - this is the horror Ive witnessed in the crackdown - The Guardian - January 26th, 2026 [January 26th, 2026]
- US Aircraft Carrier Arrives in the Middle East as Tensions With Iran Remain High - Military.com - January 26th, 2026 [January 26th, 2026]
- Italy pushes for EU clampdown on Iran's Revolutionary Guard over 'heinous acts - Reuters - January 26th, 2026 [January 26th, 2026]
- After mass killings, bodies of Iran's slain leveraged to quash dissent - - January 26th, 2026 [January 26th, 2026]
- Iran tensions: US aircraft carrier, warships arrive in Middle East - Times of India - January 26th, 2026 [January 26th, 2026]
- Italy urges EU to list Iran's Revolutionary Guards as terror group - Euronews.com - January 26th, 2026 [January 26th, 2026]
- USS Abraham Lincoln returns to the Middle East amid rising tensions with Iran - Task & Purpose - January 26th, 2026 [January 26th, 2026]
- US warships arrive in Middle East amid fears Trump will finally order Iran strike - The Independent - January 26th, 2026 [January 26th, 2026]
- Trump: Iran wants to talk, situation in flux after US sent big armada to Mideast - timesofisrael.com - January 26th, 2026 [January 26th, 2026]
- US Official Says Washington Is Open for Business if Iran Wishes to Contact Them - U.S. News & World Report - January 26th, 2026 [January 26th, 2026]
- Scale of Iran's nationwide protests and bloody crackdown come into focus even as internet is out - ABC News - January 24th, 2026 [January 24th, 2026]
- Iran's Ayatollah Khamenei moves to underground bunker amid fears of US strike - report - jpost.com - January 24th, 2026 [January 24th, 2026]
- Iran-US tensions LIVE: Trump gets new trigger ready threat from Tehran, India gets a thank you note - Hindustan Times - January 24th, 2026 [January 24th, 2026]
- 'A moment like no other': US-based think tank urges Trump to sap Iran - - January 24th, 2026 [January 24th, 2026]
- Scale of Iran's nationwide protests and bloody crackdown come into focus even as internet is out - AP News - January 24th, 2026 [January 24th, 2026]
- Iran offers first government-issued death toll from protest crackdown, one far lower than activists - AP News - January 24th, 2026 [January 24th, 2026]
- An exiled crown prince says he can lead Iran to democracy, but Trump hasn't endorsed him - NBC News - January 24th, 2026 [January 24th, 2026]
- Iran Warns Middle East Will Collapse If Government Falls Amid US Threats - Newsweek - January 24th, 2026 [January 24th, 2026]
- As Iran Grieves, Accounts Emerge of Disrespectful Treatment of Protest Victims - The New York Times - January 24th, 2026 [January 24th, 2026]
- Iran is not a major oil producer, but it still moves prices. Here's why - CNBC - January 24th, 2026 [January 24th, 2026]
- Trump sends 'massive' armada to Middle East in warning to Iran - Fox News - January 24th, 2026 [January 24th, 2026]
- Trump warns U.S. 'armada' heading to Iran; death toll in protest crackdown tops 5,000, activists say - NBC News - January 24th, 2026 [January 24th, 2026]
- Iran adopts military posture against free flow of information, report says - - January 24th, 2026 [January 24th, 2026]
- Turkey's FM says Israel still seeking chance to attack Iran - jpost.com - January 24th, 2026 [January 24th, 2026]
- The night Iran went dark: Witness accounts and video reveal violence inflicted during Irans internet blackout - CNN - January 24th, 2026 [January 24th, 2026]
- Trump Says U.S. Armada Is Heading to Iran, Raising Pressure on Regime - The New York Times - January 24th, 2026 [January 24th, 2026]
- Iran's Revolutionary Guard commander warns the US, says his force has its 'finger on the trigger' - The Independent - January 24th, 2026 [January 24th, 2026]
- Trump says US still watching Iran as massive fleet heads to Gulf region - Al Jazeera - January 24th, 2026 [January 24th, 2026]
- European air carriers scuttle Middle East service in face of US-Iran tensions - Anadolu Ajans - January 24th, 2026 [January 24th, 2026]
- Iran warns it will regard any attack as all-out war after Trump moves armada to Middle East - The Independent - January 24th, 2026 [January 24th, 2026]
- Why Qatar is betting on diplomacy with Iran - Al Jazeera - January 24th, 2026 [January 24th, 2026]
- Trump threatens Iran with crushing response as Tehran denies halting protest executions - Fox News - January 24th, 2026 [January 24th, 2026]
- US carrier strike group not within striking distance of Iran yet - Fox News - - January 24th, 2026 [January 24th, 2026]
- Inside Trumps Iran warning and the unexpected pause that followed - Fox News - January 24th, 2026 [January 24th, 2026]
- Iran's top prosecutor criticizes Trump's announcement that 800+ executions were halted: 'Completely false' - Fox News - January 24th, 2026 [January 24th, 2026]
- I am in Iran watching the protests and desperate for change. But I dont believe the regime will fall | Anonymous - The Guardian - January 24th, 2026 [January 24th, 2026]
- Western media is silent on Iran, and ignores democracy - jpost.com - January 24th, 2026 [January 24th, 2026]
- IRGC leader warns Iran has 'finger on the trigger' as it awaits US 'armada': 'More ready than ever' - New York Post - January 24th, 2026 [January 24th, 2026]
- Trump says all meetings with Iran are off until crackdown on protesters ends - CNN - January 14th, 2026 [January 14th, 2026]
- At least 2,571 killed in Iran's protests, Trump says 'help is on the way' - Reuters - January 14th, 2026 [January 14th, 2026]
- Heres What to Know About the Protests in Iran - The New York Times - January 14th, 2026 [January 14th, 2026]
- More than 2,000 people reported killed at Iran protests as Trump says 'help is on its way' - BBC - January 14th, 2026 [January 14th, 2026]
- Column | Could Iran go the way of Venezuela? - The Washington Post - January 14th, 2026 [January 14th, 2026]