logo

IRGC-Linked Hackers Package Modular Malware in Monolithic Trojan

ID: 4c43154d-7590-5ffc-a413-0e3288ded7d0

STIX ID: report--4c43154d-7590-5ffc-a413-0e3288ded7d0

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-08-20

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

A state-affiliated Iranian APT known as TA453 (aka APT42/CharmingCypress) carried out a spear-phishing operation impersonating an ISW researcher to lure an Israeli rabbi and delivered a consolidated PowerShell trojan dubbed "AnvilEcho"; the report highlights the group's shift from modular, multi-component tooling to a single-script backdoor and discusses trade-offs in detection, footprint, and deployment techniques (ZIP with LNK, staged delivery).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.