Sunday, March 26, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

Iranian Government Entities Under Attack by New Wave of BackdoorDiplomacy Attacks

justmattg by justmattg
January 18, 2023
in Cyber Security
0
Iranian Government Entities Under Attack by New Wave of BackdoorDiplomacy Attacks
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

READ ALSO

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month


Jan 18, 2023Ravie LakshmananCyber Espionage / Cyber Risk

BackdoorDiplomacy Cyber Attacks

The threat actor known as BackdoorDiplomacy has been linked to a new wave of attacks targeting Iranian government entities between July and late December 2022.

Palo Alto Networks Unit 42, which is tracking the activity under its constellation-themed moniker Playful Taurus, said it observed the government domains attempting to connect to malware infrastructure previously identified as associated with the adversary.

Also known by the names APT15, KeChang, NICKEL, and Vixen Panda, the Chinese APT group has a history of cyber espionage campaigns aimed at government and diplomatic entities across North America, South America, Africa, and the Middle East at least since 2010.

Slovak cybersecurity firm ESET, in June 2021, unpacked the intrusions mounted by hacking crew against diplomatic entities and telecommunication companies in Africa and the Middle East using a custom implant known as Turian.

Then in December 2021, Microsoft announced the seizure of 42 domains operated by the group in its attacks targeting 29 countries, while pointing out its use of exploits against unpatched systems to compromise internet-facing web applications such as Microsoft Exchange and SharePoint.

The threat actor was most recently attributed to an attack on an unnamed telecom company in the Middle East using Quarian, a predecessor of Turian that allows a point of remote access into targeted networks.

Turian “remains under active development and we assess that it is used exclusively by Playful Taurus actors,” Unit 42 said in a report shared with The Hacker News, adding it discovered new variants of the backdoor used in attacks singling out Iran.

The cybersecurity company further noted that it observed four different Iranian organizations, including the Ministry of Foreign Affairs and the Natural Resources Organization, reaching out to a known command-and-control (C2) server attributed to the group.

“The sustained daily nature of these connections to Playful Taurus controlled infrastructure suggests a likely compromise of these networks,” it said.

The new versions of the Turian backdoor sport additional obfuscation as well as an updated decryption algorithm used to extract the C2 servers. However, the malware in itself is generic in that it offers basic functions to update the C2 server to connect to, execute commands, and spawn reverse shells.

BackdoorDiplomacy’s interest in targeting Iran is said to have geopolitical extensions as it comes against the backdrop of a 25-year comprehensive cooperation agreement signed between China dn Iran to foster economic, military, and security cooperation.

“Playful Taurus continues to evolve their tactics and their tooling,” researchers said. “Recent upgrades to the Turian backdoor and new C2 infrastructure suggest that these actors continue to see success during their cyber espionage campaigns.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Related Posts

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident
Cyber Security

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

March 26, 2023
Everything You Need to Know
Cyber Security

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month

March 26, 2023
Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers
Cyber Security

Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers

March 26, 2023
U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals
Cyber Security

U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals

March 25, 2023
Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data
Cyber Security

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data

March 25, 2023
Red Teaming at Scale to Uncover Your Big Unknowns
Cyber Security

Red Teaming at Scale to Uncover Your Big Unknowns

March 24, 2023
Next Post
Touchless Biometrics Solutions Market to Witness Major Growth

Touchless Biometrics Solutions Market to Witness Major Growth

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

2023 Cybersecurity Maturity Report Reveals Organizational Unpreparedness for Cyberattacks

2023 Cybersecurity Maturity Report Reveals Organizational Unpreparedness for Cyberattacks

March 23, 2023
Cybersecurity Budgets Are Going Up. So Why Aren’t Breaches Going Down?

Cybersecurity Budgets Are Going Up. So Why Aren’t Breaches Going Down?

February 3, 2023
Mitigate the LastPass Attack Surface in Your Environment with this Free Tool

Mitigate the LastPass Attack Surface in Your Environment with this Free Tool

January 7, 2023
North Korea’s APT37 Targeting Southern Counterpart with New M2RAT Malware

North Korea’s APT37 Targeting Southern Counterpart with New M2RAT Malware

February 15, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident
  • ‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month
  • Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers
  • U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.