Targeted Iranian Attacks Against Iraqi Government Infrastructure
ID: 1c0a43f0-5dfb-573a-b081-cee94a5fbcbc
STIX ID: report--1c0a43f0-5dfb-573a-b081-cee94a5fbcbc
Feed Name: Check Point Research
Threat Score
Check Point Research uncovered a targeted campaign against Iraqi government networks deploying two new .NET backdoors—Spearal (DNS tunneling) and Veaty (email-based C2 using compromised gov mailboxes)—plus a passive IIS backdoor (CacheHttp), an HTTP listener, and SSH-tunneling tooling; the report documents detailed C2 protocols, deployment/persistence methods, IOCs (IPs, domains, sample hashes), and attributes the activity to an APT34/MOIS-linked actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
