Iranian hackers now exploit Windows flaw to elevate privileges
ID: 294f09ae-0067-51d2-8886-96eadd8df72c
STIX ID: report--294f09ae-0067-51d2-8886-96eadd8df72c
Feed Name: Bleeping Computer
APT34 (OilRig) has increased activity in the UAE and Gulf, using exploited web servers and web shells to deploy a new backdoor named StealHook that captures and exfiltrates credentials via on‑prem Microsoft Exchange servers; the actors also leverage a Windows privilege escalation (CVE-2024-30088), register a password-filter DLL, and use ngrok for covert communications, with Trend Micro observing these tactics and noting links to FOX Kitten and a focus on energy/critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
