APT39 Hacking Group Launch Widespread Attack Focused on Personal Information

Iranian cyber espionage group APT39 focus on stealing on personal information o perform monitoring, tracking, or surveillance operations against specific individuals.

The group carrying a widespread campaign focused their operations in the Middle East, the U.S. and South Korea. Following are the industries targeted including telecommunications, travel industries, high-tech industry, and government entities.

“We have moderate confidence APT39 operations are conducted in support of Iranian national interests based on regional targeting patterns focused in the Middle East, infrastructure, timing, and similarities to APT34”, reads FireEye report.

Focused Attack – APT39

The attack starts with spear phishing emails, stolen credentials, and web server compromise. Phishing emails carry malicious attachments resulting in downloading the POWBAT malware.

For C2 server communications the hacker group register domains that pose as a legitimate one and relevant to organizations.

Also, the group compromise web servers with know vulnerabilities of the targeted organizations and inject web shells such as ANTAK and ASPXSPY. Stolen credentials used to gain access to the email accounts.

APT39 uses custom backdoors such as SEAWEED, CACHEMONEY variants of POWBAT to gain access to the target organizations and to escalate privileges using freely available tools such as Mimikatz and Ncrack.

Lateral movement carried out through popular tools such as Remote Desktop Protocol (RDP), Secure Shell (SSH), PsExec, RemCom, xCmdSvc and with custom tools REDTRIP, PINKTRIP, and BLUETRIP.

To archive, the stolen data the APT 39 group uses WinRAR or 7-Zip and they use a modified version of Mimikatz to evade anti-virus detection.

Telecommunication and travel industries are the prime targets for the group as they as they store large amounts of personal and customer information,

“APT39’s targeting not only represents a threat to known targeted industries, but it extends to these organizations’ clientele, which includes a wide variety of sectors and individuals on a global scale,” researchers concluded.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Related Read

APT Group Actively Exploiting Internet-facing Vulnerable ColdFusion Server and Uploading Webshell

APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands

APT28 Hacking Group’s New Espionage Operations Targets Military and Government Organizations

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently detailed…

2 hours ago

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria Stealer,"…

2 hours ago

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton Pass,…

2 hours ago

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly sophisticated…

2 hours ago

Hackers Impersonate Top Tax Firm with 40,000 Phishing Messages to Steal Credentials

Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations designed…

2 hours ago

Cybercriminals Exploit Public-Facing IIS, Apache, and SQL Servers to Breach Gov & Telecom Systems

A recent investigation by Unit 42 of Palo Alto Networks has uncovered a sophisticated, state-sponsored…

2 hours ago