logo

Iran’s Mint Sandstorm APT Hits Universities with Hamas-Israel Phishing Scam

ID: 2e60edf4-a0b6-58a0-8201-aa2dae1fa62f

STIX ID: report--2e60edf4-a0b6-58a0-8201-aa2dae1fa62f

Feed Name: HackRead

Threat Score
85/100

Date Published: 2024-01-19

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Microsoft warns that Iran-linked Mint Sandstorm (APT35) is running a sophisticated phishing campaign targeting high-profile researchers working on the Israel–Hamas conflict, leveraging compromised legitimate email accounts and benign-seeming lures to deliver a custom backdoor (MediaPl / MediaPI). The attack chain involves RAR archives unpacking double-extension .pdf.lnk files that execute curl to retrieve additional payloads from attacker-controlled subdomains; observed artifacts include .vbs persistence scripts, a renamed NirCmd binary, and malicious domains. Microsoft observed activity across the UK, USA, Belgium, France, Gaza, and Israel and recommends user training, SmartScreen-enabled browsers, network protection, and cloud-delivered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.