New Iranian hacker backdoor evades security products

By
Follow google news

Phosphorus APT targets medical research and academic organisations.

Security researchers have discovered that an Iranian advanced persistent threat (APT) group is using a novel trick to avoid detection of malicious PowerShell code.

New Iranian hacker backdoor evades security products

Cybereason said it had found a new toolkit used by the Phosphorus group, also known as Charming Kitten and APT35, that installs malicious Microsoft PowerShell code to operate as a remote access backdoor to download further malware payloads.

The hackers, who are said to be Iranian state-sponsored, run the malicious PowerShell code in the context of a .NET programming framework application, which means the powershell.exe binary is not launched, Cybereason said.

This stealth technique lets the hackers run their code without triggering alerts from security products.

The new Phosphorus toolkit is modular and multistaged, with active command and control infrastructure, some of which is shared with the Memento ransomware, the researchers noted.

Phosphorus has attacked research facilities and academic organisations in the United States and Israel in the past few years, as well as Europe and other Middle East nations.

The groups is believed to specialise in espionage and attacks against enemies of Iran.

Cybereason said Phosphorus has been active over the past months, using publicised exploits such as ProxyShell against Microsoft Exchange Server for ransomware attacks.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?