تمت ترجمة هذا النص بواسطة الذكاء الاصطناعي وقد يحتوي على أخطاء.
تخطي إلى المحتوى
  • التحليل
  • Iranian APTs: An overview

    February 10, 2023

    Steph Shample
    Steph Shample

    Artificial Intelligence (AI), Cybersecurity, Emerging Technologies, Technology

    In this photo illustration, a hacker with an Anonymous mask on his face and a hood on his head uses a computer on December 27, 2019 in Paris, France. In IT security, a hacker is an IT specialist, who is looking for ways to bypass software and hardware protections. Hackers are generally intelligent programmers who seek to manipulate or modify a computer system or network. (Photo by Chesnot/Getty Images)
    In this photo illustration, a hacker with an Anonymous mask on his face and a hood on his head uses a computer on December 27, 2019 in Paris, France. In IT security, a hacker is an IT specialist, who is looking for ways to bypass software and hardware protections. Hackers are generally intelligent programmers who seek to manipulate or modify a computer system or network. (Photo by Chesnot/Getty Images)

     

    Introduction

    Cyber security experts have identified eight different groups attributed to the Islamic Republic of Iran. These actors are identified forensically by common tactics, techniques, and procedures, as well as similarities in their code and the industries that they target; this attribution is not based on human intelligence inside the Iranian government. Chinese Advanced Persistent Threat (APT) actors are commonly known as “Pandas,” Russian APTs as “Bears,” and Iranian APTs as “Kittens” (yes, really).

    This page is maintained by MEI’s Strategic Technologies & Cyber Security Program.

     

     

     

     

    “Due to the obfuscation techniques, and government control over the Iranian media and internet, we don’t have insight into which APT is Ministry of Intelligence vs. IRGC. What we can do is track their tools like malware, efforts like spear-phishing and brute-forcing, and maintain awareness to increase protection.”

     

     

    Iranian APTs


     

    APT 33

    APT 33

    Also known as Elfin, Refined Kitten

    First active: 2013

    Last observed: 2019

    Malware

    • SHAPESHIFT
    • DROPSHOT/Stonedrill
    • TURNEDUP
    • NANOCORE
    • ALFA Shell
    • NETWIRE

    Initial attack vector

    Additional Information

     

    APT 34

    APT 34

    Also known as OilRig, Helix Kitten, GreenBug, IRN2

    First active: 2014

    Last observed: 2021

    Malware

    • ZEROCLEARE
    • DNSPIONAGE
    • PICKPOCKET
    • VALUEVAULT
    • LONGWATCH

    Initial attack vector

    • Social Engineering, Social Media Phishing, Spearphishing
      • Academia-themed conversations
      • Malicious document (.doc) delivery
      • Using LinkedIn messaging to send malicious links
      • Use of various social media platforms for the above
    • Other tools & methods
    • Common vulnerabilities & exploits (CVEs)

    Additional information

     

    APT 35

    APT 35

    Also known as Newscaster, Rocket Kitten, Phosphorus, Charming Kitten, Saffron Rose

    First active: 2014

    Last observed: 2022

    Ransomware use

    • Momento
    • Bitlocker

    Malware

    • PowerLess
    • HAVIJ

    Initial attack vector

    • Social Engineering, Social Media Phishing, Spearphishing
      • Password Recovery Impersonation
      • SMS Spearphishing
      • Use of various social media platforms for the above
    • Other tools & methods:
      • Two-Factor Authentication Defeat
      • Keylogging
      • Mimikatz
      • Microsoft Office vulnerability abuse
      • IP logging
      • Ransomware

    Additional information

     

    APT 39

    APT 39

    Also known as Chafer, Remix Kitten

    First active: 2014

    Last observed: 2020

    Malware

    • BITS 1.0 and 2.0
    • VBS
    • Autolt
    • SEAWEED
    • CACHEMONEY
    • POWBAT

    Initial attack vector

    • Spearphishing
      • Malicious attachments
      • URLs infected with POWBAT
      • Use of various social media platforms for the above
    • Other tools & methods:
      • Run the front company Rana
      • Vulnerable web servers
      • Custom backdoors
      • Mimikatz
      • SQL injections
    • RDPSSHdata compression before exfiltration

    Additional information

     

    APT42

    APT 42

    Also known as Crooked Charms, TA453

    First active: 2011

    Last observed: 2022

    Malware

    • VINETHORN
    • PINEFLOWER
    • BROKEYOLK

    Initial attack vector

    • Highly targeted spearphishing, social engineering, election meddling
      • TAMECAT powershell backdoor
      • Malicious document (.doc) delivery
        • Via Google drive links
        • Google books links
      • Credential harvesting
    • Other tools & methods:
      • Google Takeout
      • False registration and login pages
      • Keylogging
      • Cookie stealing
      • Notable overlap with APT35 TTPs

    Additional information

    Rampant Kitten

    Rampant Kitten

    First active: 2014

    Last observed: 2020

    Malware  

    • Information stealing variants, primarily targeting KeePass and Telegram accounts of intended victims
    • Dharma ransomware

    Initial attack vector

    • Employ information stealers to target credentials, personal documents, SMS, and Telegram messages
      • An Android backdoor extracts two-factor authentication codes
      • Phishing pages masquerading as distributors of fake accounts
      • Bypassing two- and multi-factor authentication
    • Other tools/methods: VPN exploitation
    • CVEs 
      • CVE-2019-11510
      • CVE-2019-19781
      • CVE-2020-5902

    Additional information

    • Goals:
      • Espionage
      • Target and expose/dox dissidents/Iranian minorities
      • Financial gain
    • Countries targeted:
      • Russia 
      • Japan
      • China
      • India
      • إسرائيل
      • North America
    • Industries targeted:
      • Government
      • التكنولوجيا
      • Defense
    • Further reading:

     

     

    Pioneer Kitten

    Pioneer Kitten

    Also known as Fox Kitten, PARISITE, UNC757

    First active: 2017

    Last observed: 2020

    Initial attack vector

    • Exploits unpatched vulnerabilities
    • Webshells
    • SSH Tunneling
      • VPN Exploitation
    • Other tools/methods: Sells access to compromised systems and networks
    • CVEs 
      • CVE-2018-13379
      • CVE-2019-11510
      • CVE-2019-19781
      • CVE-2020-5902

    Additional information

     

     

    Static Kitten

    Static Kitten

    Also known as MUDDYWATER, Seedworm

    First active: 2017

    Last observed: 2021

    Malware 

    • POWERSTATS powershell trojan
    • PowGoop

    Initial attack vector

    • Spearphishing
      • Malicious document and file (.doc, .zip) delivery
      • Malicious use of common open-source tools
    • Other tools/methods: Powershell scripts, ScreenConnect, RemoteUtilities, custom backdoors, lateral movement within networks
    • CVEs 

    Additional information


    معهد الشرق الأوسط (MEI) هو منظمة تعليمية مستقلة وغير حزبية وغير ربحية. لا يشارك المعهد في أي أنشطة دعوية، وآراء الباحثين فيه تعبر عن آرائهم الشخصية. يرحب المعهد بالتبرعات المالية، لكنه يحتفظ بالسيطرة التحريرية الكاملة على أعماله، ولا تعكس منشوراته سوى آراء المؤلفين. للاطلاع على قائمة المتبرعين للمعهد، يرجى النقر هنا.

    المزيد من هذا القبيل