logo

Iran's MOIS-Linked APT34 Spies on Allies Iraq & Yemen

ID: a05a5101-f12b-53ba-b44a-46ae7d3c4d83

STIX ID: report--a05a5101-f12b-53ba-b44a-46ae7d3c4d83

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-28

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Check Point researchers report ongoing APT34 (Iran-linked) cyberespionage against Iraqi government targets and Yemeni organizations, using phishing-delivered custom backdoors (Veaty, Spearal), SSH and DNS tunneling, and a PowerShell backdoor ('Power Service'); activity persisted into 2025 and appears to involve multiple subgroups sharing tools and infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.