logo

Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor

ID: b1483914-6da2-5442-a3f7-4ec94cd31f69

STIX ID: report--b1483914-6da2-5442-a3f7-4ec94cd31f69

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Charming Kitten (APT35) ran targeted phishing campaigns against Middle East policy experts using a fake webinar portal and multi-persona impersonation to deliver backdoors such as BASICSTAR and KORKULOADER, with OS-specific follow-ons (Windows: PowerLess; macOS: NokNok). The report highlights persistent social-engineering TTPs, observed active exploitation in Sep–Oct 2023, and ties between the group's operations and IRGC-affiliated contractor networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.