Iranian hackers have been targeting the aerospace industry using fake job offers to deliver malware, according to a recent report by cybersecurity firm ClearSky. The attacks are attributed to TA455, also known as Smoke Sandstorm or Bohrium, a subgroup of the Iran-linked APT group Charming Kitten (APT35). These campaigns resemble the "dream job" tactics previously associated with North Korea's APT group Lazarus. ClearSky speculates that Charming Kitten may either be mimicking Lazarus to obscure its activities or has access to the same tools and techniques. Some malware samples have been flagged by antivirus systems as belonging to Kimsuky or Lazarus rather than Charming Kitten. Active since September 2023, the Iranian campaign uses fake job offers to trick victims into downloading SnailResin malware. The malware is delivered from a website impersonating a legitimate job recruitment platform, which also displays a LinkedIn profile for the recruiter. ClearSky notes that the profiles used are updated versions of ones identified earlier in 2024 by Mandiant in a cyberespionage campaign targeting aerospace, aviation, and defense sectors in the Middle East. TA455 uses spear-phishing emails containing ZIP attachments with fake job documents and legitimate files designed to bypass security detection. Once opened, the malicious documents execute system fingerprinting to gather information about the victim's device. To further evade detection, the group leverages legitimate platforms like Cloudflare, GitHub, and Microsoft Azure to hide its command-and-control (C&C) infrastructure and employs a multi-stage infection process. Additionally, the use of LinkedIn profiles adds credibility to their campaigns, making it easier to deceive targets. ClearSky highlights that TA455’s continuous updates to its infrastructure, tools, and malware demonstrate its adaptability and sustained effort to evade security defenses, underscoring the persistent nature of the threat.
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...
A large-scale Android malware campaign known as NoVoice was discovered on Google Play, where over 50 seemingly legitimate applications were used to distribute malicious code. These...
A recent cyber campaign has been observed targeting procurement and sales professionals through RFQ (Request for Quotation) themed phishing emails. Attackers impersonate legitimate...