OilRig campaign

Pierluigi Paganini December 07, 2017
HBO hacker linked to the Iranian Charming Kitten APT group

A new report published by¬†ClearSky linked a¬†man accused by U.S. authorities of hacking into the systems of HBO to the Iranian cyber espionage group Charming Kitten. Experts from the security firm ClearSky have published a new detailed report on the activities of Charming Kitten¬†APT group, also known as Newscaster and NewsBeef. The¬†Newscaster¬†group made the headlines […]

Pierluigi Paganini October 10, 2017
Iran-linked OilRig hacked group use a new Trojan in Middle East Attacks

The Iran-Linked cyberespionage group OilRig has been using a new Trojan in attacks aimed at targets in the Middle East. Experts from¬†Palo Alto Networks spotted a new campaign launched by the notorious APT group OilRig¬†against an organization within the government of the United Arab Emirates (UAE). The¬†OilRig¬†hacker group¬†is an¬†Iran-linked¬†APT that has been around since¬†at least […]

Pierluigi Paganini April 28, 2017
The massive attack against Israel was alleged launched by the Iranian OilRig APT group

According to the experts at the security firm Morphisec that massive attack against Israeli targets was powered by the OilRig APT group. Yesterday the¬†Israeli Cyber Defense Authority announced¬†it has thwarted a major cyberattack against 120 targets just days after harsh criticism of new cyber defense bill. In a first time, the authorities blamed a foreign […]

Pierluigi Paganini October 08, 2016
OilRig campaign, Iran-Linked Hackers Target US Government & Energy Grid

OilRig campaign – An Iran-linked hacker group which previously targeted organizations in Saudi Arabia has now set its sights on other countries. Iranian hackers which¬†previously¬†targeted¬†organizations¬†in¬†Saudi¬†Arabia are now targeting organizations in other¬†countries, including¬†the¬†US, as part of a campaign identified as¬†OilRig campaign. In¬†addition¬†to¬†expanding¬†its¬†reach,¬†the¬†group¬†has¬†been¬†enhancing¬†its¬†malware¬†tools. Researchers¬†at¬†Palo¬†Alto¬†Networks¬†have¬†been¬†monitoring¬†the¬†group¬†for¬†some¬†time¬†and¬†have¬† reported¬†observing¬†attacks¬†launched¬†by¬†a¬†threat¬†actor¬†against¬†financial¬†institutions¬†and¬†technology¬† companies¬†in¬†Saudi¬†Arabia¬†and¬†on¬†the¬†Saudi¬†defense¬†industry.¬†This¬†campaign¬†referred¬†to¬†as¬†‚ÄúOilRig,‚Ä̬†by¬†Palo¬†Alto¬†Networks,¬†entails¬†weaponized¬†Microsoft¬†Excel¬†spreadsheets¬†tracked¬†as¬† ‚ÄúClayslide‚Ä̬†and¬†a¬†backdoor¬†called¬†‚ÄúHelminth.‚Ä̬†¬† Bank¬†attacks¬†by¬†the¬†Iran-linked¬†group¬†were¬†analyzed¬†and¬†documented¬†by¬†FireEye¬†in¬†May.¬†Security¬† Week¬†reports¬†that¬†Palo¬†Alto¬†Networks,¬†‚Äúdiscovered¬†that¬†it¬†has¬†also¬†targeted¬†a¬†company¬†in¬†Qatar¬† and¬†government¬†organizations¬†in¬†the¬†United¬†States,¬†Israel¬†and¬†Turkey.‚Ä̬† Helminth¬†is¬†delivered,¬†by¬†the¬†threat¬†actors¬†behind¬†OilRig,¬†by¬†way¬†of¬†spear-phishing¬†emails¬†and¬† malicious¬†macro-enabled¬†Excel¬†documents.¬†For¬†instance,¬†in¬†the¬†caseof¬†a¬†Turkish¬†government¬†organization,¬†the¬†Excel¬†file¬†was¬†designed¬†to¬†replicate¬†a¬†login¬†portal¬†for¬†an airline.¬† There¬†are¬†four¬†variants¬†of¬†the¬†Helminth¬†malware¬†and¬†the¬†threat,¬†capable¬†of¬†communicating¬†with¬†its¬† command¬†and¬†control¬†(C&C)¬†server¬†over¬†both¬†HTTP¬†and¬†DNS,¬†can¬†gain¬†information¬†on¬†the¬† infected¬†device¬†and¬†download¬†additional¬†files¬†via¬†a¬†remote¬†server.¬†One¬†type¬†of¬†Helminth¬†malware¬† relies¬†on¬†VBScript¬†and¬†PowerShell¬†scripts.¬†Another¬†is¬†deployed¬†as¬†an¬†executable¬†file.¬†Delivered¬†by¬† […]