logo

Iranian hackers now exploit Windows flaw to elevate privileges

ID: 294f09ae-0067-51d2-8886-96eadd8df72c

STIX ID: report--294f09ae-0067-51d2-8886-96eadd8df72c

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

APT34 (OilRig) has increased activity in the UAE and Gulf, using exploited web servers and web shells to deploy a new backdoor named StealHook that captures and exfiltrates credentials via on‑prem Microsoft Exchange servers; the actors also leverage a Windows privilege escalation (CVE-2024-30088), register a password-filter DLL, and use ngrok for covert communications, with Trend Micro observing these tactics and noting links to FOX Kitten and a focus on energy/critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.