Iranian hackers pose as journalists to push backdoor malware
ID: 1a64290e-bae4-5d49-a1f6-c5bc9671274b
STIX ID: report--1a64290e-bae4-5d49-a1f6-c5bc9671274b
Feed Name: Bleeping Computer
APT42, an Iranian state-linked threat actor, is running targeted spear-phishing campaigns that impersonate journalists and organizations to steal credentials (including MFA) and deliver custom backdoors — Nicecurl (VBScript) and Tamecat (PowerShell) — to gain access to corporate and cloud environments, exfiltrate emails/documents, and blend with normal cloud operations; the report details the social-engineering lures, infrastructure choices (typosquatted domains, ExpressVPN, Cloudflare, ephemeral VPS), and references IoCs and YARA rules for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
