logo

Iran's APT34 Abuses MS Exchange to Spy on Gulf Gov'ts

ID: 021d09e2-d226-5c84-ad21-aff75a7b0142

STIX ID: report--021d09e2-d226-5c84-ad21-aff75a7b0142

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-10-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Trend Micro and other researchers report a notable rise in espionage by APT34 against Gulf-state government organizations, especially in the UAE. The actor uses web shells to deploy tools (including ngrok) for C2, a new backdoor named StealHook to harvest Exchange and domain credentials and exfiltrate data via mail attachments, and exploits CVE-2024-30088 plus a malicious Windows password filter DLL to obtain elevated and plaintext credentials—facilitating lateral movement and supply-chain follow-on attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.