Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor
ID: b1483914-6da2-5442-a3f7-4ec94cd31f69
STIX ID: report--b1483914-6da2-5442-a3f7-4ec94cd31f69
Feed Name: The Hacker News
Threat Score
Charming Kitten (APT35) ran targeted phishing campaigns against Middle East policy experts using a fake webinar portal and multi-persona impersonation to deliver backdoors such as BASICSTAR and KORKULOADER, with OS-specific follow-ons (Windows: PowerLess; macOS: NokNok). The report highlights persistent social-engineering TTPs, observed active exploitation in Sep–Oct 2023, and ties between the group's operations and IRGC-affiliated contractor networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
