Microsoft: Iranian hackers target researchers with new MediaPl malware
ID: 02402656-0fe3-5427-9d63-89214a4dd730
STIX ID: report--02402656-0fe3-5427-9d63-89214a4dd730
Feed Name: Bleeping Computer
Microsoft observed an Iranian-backed APT35 subgroup (Mint Sandstorm/Phosphorus) conducting bespoke spearphishing campaigns since November 2023, targeting high-profile individuals at universities and research organizations in Belgium, France, Gaza, Israel, the UK, and the US. The attackers used compromised accounts and impersonation (including posing as journalists) to deliver custom backdoors: MediaPl (masquerades as Windows Media Player, uses AES-CBC + Base64 for C2, supports auto-terminate and remote command execution) and a PowerShell-based backdoor dubbed MischiefTut for dropping tools and reconnaissance. The campaign appears focused on collecting sensitive perspectives and intelligence related to Middle Eastern affairs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
