Iran's MOIS-Linked APT34 Spies on Allies Iraq & Yemen
ID: a05a5101-f12b-53ba-b44a-46ae7d3c4d83
STIX ID: report--a05a5101-f12b-53ba-b44a-46ae7d3c4d83
Feed Name: Dark Reading
Threat Score
Check Point researchers report ongoing APT34 (Iran-linked) cyberespionage against Iraqi government targets and Yemeni organizations, using phishing-delivered custom backdoors (Veaty, Spearal), SSH and DNS tunneling, and a PowerShell backdoor ('Power Service'); activity persisted into 2025 and appears to involve multiple subgroups sharing tools and infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
