logo

Iranian hackers pose as journalists to push backdoor malware

ID: 1a64290e-bae4-5d49-a1f6-c5bc9671274b

STIX ID: report--1a64290e-bae4-5d49-a1f6-c5bc9671274b

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-05-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

APT42, an Iranian state-linked threat actor, is running targeted spear-phishing campaigns that impersonate journalists and organizations to steal credentials (including MFA) and deliver custom backdoors — Nicecurl (VBScript) and Tamecat (PowerShell) — to gain access to corporate and cloud environments, exfiltrate emails/documents, and blend with normal cloud operations; the report details the social-engineering lures, infrastructure choices (typosquatted domains, ExpressVPN, Cloudflare, ephemeral VPS), and references IoCs and YARA rules for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.