New AI-Developed Malware Campaign Targets Iranian Protests
ID: 488d5567-a0dc-5a04-84aa-de4180edaeda
STIX ID: report--488d5567-a0dc-5a04-84aa-de4180edaeda
Feed Name: Infosecurity Magazine (News)
**Executive summary:** HarfangLab discovered a targeted campaign (RedKitten) delivering a C# implant called SloppyMIO via password-protected, macro-enabled Excel lures that appear to be forensic lists of protest victims in Iran; the malware supports data theft, remote command execution, modular payload downloads (via GitHub/Google Drive), steganographic configuration, Telegram C2, and persistence, and researchers assessed the activity as likely aligned with Iranian state interests and partially developed using LLM tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
