New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE Government

Teilen:

An unnamed government entity associated with the United Arab Emirates (U.A.E.) was targeted by a likely Iranian threat actor to breach the victim’s Microsoft Exchange Server with a “simple yet effective” backdoor dubbed PowerExchange.

According to a new report from Fortinet FortiGuard Labs, the intrusion relied on email phishing as an initial access pathway, leading to the execution of a .NET executable contained with a ZIP file attachment.

The binary, which masquerades as a PDF document, functions as a dropper to execute the final payload, which then launches the backdoor.

PowerExchange, written in PowerShell, employs text files attached to emails for command-and-control (C2) communication. It allows the threat actor to run arbitrary payloads and upload and download files from and to the system.

 

 

The custom implant achieves this by making use of the Exchange Web Services (EWS) API to connect to the victim’s Exchange Server and uses a mailbox on the server to send and receive encoded commands from its operator.

“The Exchange Server is accessible from the internet, saving C2 communication to external servers from the devices in the organizations,” Fortinet researchers said. “It also acts as a proxy for the attacker to mask himself.”

Microsoft Exchange backdoor

That said, it’s currently not known how the threat actor managed to obtain the domain credentials to connect to the target Exchange Server.

Fortinet’s investigation also uncovered Exchange servers that were backdoored with several web shells, one of which is called ExchangeLeech (aka System.Web.ServiceAuthentication.dll), to achieve persistent remote access and steal user credentials.

PowerExchange is suspected to be an upgraded version of TriFive, which was previously used by the Iranian nation-stage actor APT34 (aka OilRig) in intrusions targeting government organizations in Kuwait.

Furthermore, communication via internet-facing Exchange servers is a tried-and-tested tactic adopted by the OilRig actors, as observed in the case of Karkoff and MrPerfectionManager.

“Using the victim’s Exchange server for the C2 channel allows the backdoor to blend in with benign traffic, thereby ensuring that the threat actor can easily avoid nearly all network-based detections and remediations inside and outside the target organization’s infrastructure,” the researchers said.

 

(c) Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:56 am, März 14, 2025
Wetter-Symbol -0°C
L: -2° | H: 1°
wenige Wolken
Luftfeuchtigkeit: 91 %
Druck: 1009 mb
Wind: 3 mph N
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 12%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:16 am
Sonnenuntergang: 6:02 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
-2° | 1°°C 0.86 mm 86% 7 mph 91 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
1° | 8°°C 0.2 mm 20% 12 mph 93 % 1025 mb 0 mm/h
So. März 16 9:00 pm
Wetter-Symbol
1° | 8°°C 0 mm 0% 9 mph 90 % 1027 mb 0 mm/h
Mo. März 17 9:00 pm
Wetter-Symbol
4° | 7°°C 0 mm 0% 13 mph 92 % 1028 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
-0° | 1°°C 0 mm 0% 3 mph 91 % 1009 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
1° | 4°°C 0 mm 0% 5 mph 88 % 1009 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
4° | 5°°C 0 mm 0% 6 mph 77 % 1011 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0.69 mm 69% 7 mph 71 % 1013 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0.86 mm 86% 5 mph 71 % 1014 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 5 mph 77 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 80 % 1019 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 5 mph 87 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,588.56
-1.36%
Ethereum(ETH)
€1,746.23
1.39%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.12
2.69%
Solana(SOL)
€115.14
1.14%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.155583
0.37%
Shiba Inu(SHIB)
€0.000011
1.27%
Pepe(PEPE)
€0.000006
-0.03%
Nach oben scrollen