Microsoft: Iran's Mint Sandstorm APT Blasts Educators, Researchers
ID: cd12241f-9f49-595e-b96c-afe610068dd1
STIX ID: report--cd12241f-9f49-595e-b96c-afe610068dd1
Feed Name: Dark Reading
Microsoft and industry reporting attribute a targeted espionage campaign to the Iran-linked Mint Sandstorm group (overlapping with APT35/Charming Kitten) that uses patient, highly skilled social engineering — often posing as journalists or researchers and leveraging compromised accounts — to trick academics, journalists, and policy experts into opening malicious RAR links. Successful engagements lead to deployment of custom backdoors (MediaPI and MischiefTut) and likely credential compromise to facilitate long-term surveillance and data theft, representing a sophisticated nation-state threat to researchers and institutions covering Middle Eastern and Iran-related topics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
