ZeroHour
CyberScooppublished ()ingested @snlyngaas

APT33 has used botnets to infect targets in the U.S. and Middle East, researchers say

criticalMalwareimportance 55
Full article748 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The Iranian hackers also set up their own virtual private network with “exit nodes" that change frequently, according to Trend Micro.

The Thanos ransomware used in the attacks has gained traction on underground forums (Getty Images).

An Iranian government-linked hacking group has in the last year been using small clusters of hijacked computers to infect a handful of targets that include a U.S. national security firm and a university, researchers said Thursday.

The Iranian group, dubbed APT33, is using the botnets — groups of computers commandeered by attackers — in “extremely targeted malware campaigns against organizations in the Middle East, the U.S., and Asia,” cybersecurity company Trend Micro said.

Botnets are often comprised of a large number of machines. But in this case, the Iranian hackers are using just a dozen computers per botnet to deliver their malware and get persistent access on a network, according to the researchers.

The Iranian hackers also set up their own virtual private network with “exit nodes” that change frequently, Trend Micro said. The researchers say they have been tracking those VPN nodes for over a year, but the group has likely used them for longer.

APT33 is using some of those IP addresses to do “reconnaissance on the network of an oil exploration company and military hospitals in the Middle East, as well as an oil company in the U.S.,” the researchers wrote in a blog.

APT33 is one of multiple well-resourced hacking groups researchers say are working on behalf of Iran’s interests. APT33 has vigorously gone after targets in Saudi Arabia and “a number of Fortune 500” companies in the U.S., cybersecurity company Symantec said in March.

The latest findings on APT33, which is also known as Elfin, shine new light on the group’s infrastructure and how it uses it.

The Iranian hackers are using their VPN network to access the websites of penetration-testing firms and sites related to cryptocurrencies, according to Trend Micro.  “APT33 also has a clear interest in websites that specialize in the recruitment of employees in the oil and gas industry,” they wrote.

The group has been willing to take over high-profile victim’s infrastructure for long periods of time. For at least two years, the hackers used the website of a prominent European politician to send spearphishing lures to companies in the oil-industry supply chain, Trend Micro said. Among the targets of those malicious emails was a water facility used by the U.S. army.

At least some of the lures APT33 sent from the European politician’s website were effective, the researchers added. Last year, a Britain-based oil company’s computer server was communicating with one of APT33’s servers, indicating an infection.

More Scoops

Niger River, Segou, Segou, Mali; Sascha Grabow, Getty Images

Iranian hackers ‘tickle’ targets in US, UAE with custom tool, Microsoft says

Peach Sandstorm is said to have focused on the oil and gas, satellite, government and communications sectors.

Iranian flag waving with cityscape on background in Tehran, Iran. (Sir Francis Canker Photography/Getty Images)
Iranian flag waving with cityscape on background in Tehran, Iran. (Sir Francis Canker Photography/Getty Images)

Microsoft: Iranian espionage campaign targeted satellite and defense sectors

router, hardware, botnet, cyclopsblink
Ethernet cables are seen running from the back of a wireless router in Washington, D.C., on March 21, 2019. (Photo credit should read MANDEL NGAN/AFP via Getty Images)

Sandworm-linked botnet has another piece of hardware in its sights

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apt33-iran-botnet-trend-micro/