Monday, February 17, 2025
HomeCyber Security NewsGoogle Uncovered Tool used by Iranian APT Hackers to Steal Email Data

Google Uncovered Tool used by Iranian APT Hackers to Steal Email Data

Published on

SIEM as a Service

Follow Us on Google News

There has been an addition to the Iranian APR group Charming Kitten’s malware arsenal recently with the addition of a new malicious tool. This newly added tool authorizes the threat actors to retrieve user data from the following accounts:- 

  • Gmail
  • Yahoo!
  • Microsoft Outlook

The tool was discovered by Google’s Threat Analysis Group (TAG) and is called Hyperscrape. By initiating a fake session or stealing credentials, the attacker will pose as a legitimate user in order to initiate the authentication process. 

After successful execution, it downloads the whole inbox of the targeted victim by running the scraper.

Charming Kitten

As a government-sponsored organization, Charming Kitten targets high-risk users regularly. In addition to being a prolific APT, Charming Kitten is also thought to be tied to Iran’s IRGC.

Approximately two dozen Iranian accounts were targeted. Currently, the tool is in active development, with the oldest sample dating back to 2020. Cybersecurity analysts have notified the victims that their accounts have been compromised and will need to be resecured.

The primary aim of the threat actor is espionage and financial gains, and this has been clarified after tracking and analyzing the following groups:-

  • APT35
  • Cobalt Illusion
  • ITG18
  • Phosphorus
  • TA453
  • Yellow Garuda

Hyperscrape

This malware, Hyperscrape, is written in .NET and runs primarily on Windows-based machines. Among the features of this tool is the capability of obtaining information from an email inbox and exfiltrating its contents.

There are even instances in which it can delete security emails that are sent to the target by Google, alerting them to a suspicious login attempt.

As soon as the tool opens and downloads the email as an “.eml” file, the messages are marked as unread. Hyperscrape previously had the ability to request data from Google Takeout as a feature in earlier versions of the program. 

Among the features that Google Takeout offers are the ability to export your data to an archive file that can be downloaded.

This tool launches an HTTP GET request to a C2, and if it does not find the “OK” response body in the response body, then it will terminate.

A hardcoded string was used to store C2, which was unobfuscated in the version tested. There was also an obfuscation method called Base64 used in later versions.

There would be a new form appearing within the system that will allow the operator to drag and drop the cookie file path into a new field if it was not supplied via the command line.

Hyperscrape’s Actions

For every email found, it performs the following actions:-

  • Clicks on the email and opens it
  • Downloads it
  • If the email was originally unread, mark it as unread
  • Goes back to the inbox

There is a folder called Downloads where the emails are saved with the extension “.eml”. Counts of the emails that have been downloaded are recorded in a log file.

There was a previous occurrence of the group making use of a custom surveillance program called LittleLooter for Android. An implant with a rich set of features capable of gathering sensitive data from compromised devices.

However, for now, the experts at TAG have confirmed that all the compromised account holders were notified about this incident to secure their accounts.

Secure Azure AD Conditional Access – Download Free White Paper

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Ransomware Gangs Encrypt Systems 17 Hours After Initial Infection

Ransomware gangs are accelerating their operations, with the average time-to-ransom (TTR), the period between...

Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers

Security researchers have uncovered sophisticated malware targeting WordPress websites, leveraging hidden backdoors to enable...

Xerox Printer Vulnerability Exposes Authentication Data Via LDAP and SMB

A critical security vulnerability in Xerox’s Versalink C7025 Multifunction Printer (MFP) has been uncovered,...

New XCSSET Malware Targets macOS Users Through Infected Xcode Projects

Microsoft Threat Intelligence has identified a new variant of the XCSSET macOS malware, marking...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Ransomware Gangs Encrypt Systems 17 Hours After Initial Infection

Ransomware gangs are accelerating their operations, with the average time-to-ransom (TTR), the period between...

Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers

Security researchers have uncovered sophisticated malware targeting WordPress websites, leveraging hidden backdoors to enable...

Xerox Printer Vulnerability Exposes Authentication Data Via LDAP and SMB

A critical security vulnerability in Xerox’s Versalink C7025 Multifunction Printer (MFP) has been uncovered,...