Beste Vorsätze: TA453 zielt auf religiöse Figur mit gefälschter Podcast-Einladung und liefert neues BlackSmith Malware-Toolset

Teilen:
Category Einzelheiten
Threat Actors Iranian Threat actor TA453 (Charming Kitten), likely supporting Iranian government interests, specifically the IRGC Intelligence Organization (IRGC-IO).
Campaign Overview Fake podcast invitation sent to a religious figure, leading to the delivery of BlackSmith malware, specifically the AnvilEcho PowerShell Trojan. Targeted intelligence gathering.
Target Regions (Victims) High-profile targets, including a prominent Jewish figure and likely other political and diplomatic entities.
Methodology Social engineering through multi-email phishing and fake podcast invitations. Use of ZIP archives, LNK files, and obfuscated PowerShell scripts to deliver malware.
Product Targeted Intelligence gathering and exfiltration using PowerShell malware, mainly targeting political and diplomatic figures.
Malware Reference BlackSmith malware toolkit (AnvilEcho PowerShell Trojan). Previous tools include GorjolEcho, PowerStar, and MischiefTut.
Tools Used LNK files, PowerShell, ZIP archives, steganography (used in Beautifull.jpg), various DLL files (soshi.dll, toni.dll), C++ toolset for BlackSmith, and various network C2 servers.
Vulnerabilities Exploited Malware uses multiple evasion techniques, such as bypassing SSL certificate validation, disabling antivirus detection, and obfuscating execution paths.
TTPs Phishing with fake invitations, PowerShell scripting for remote access, use of encrypted C2 channels, and exfiltration via FTP/Dropbox.
Attribution TA453 is assessed to operate in support of the IRGC-IO, with links to other Iranian-aligned threat groups (e.g., APT42).
Recommendations Enhanced phishing detection, network monitoring for unusual traffic, and blocking known C2 domains.
Quelle Proofpoint analysis of the malware and campaign, with references to various external sources confirming TA453’s activities.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:27 pm, Juni 14, 2025
Wetter-Symbol 18°C
L: 17° | H: 19°
broken clouds
Luftfeuchtigkeit: 64 %
Druck: 1018 mb
Wind: 14 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 79%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:18 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 8 mph 64 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
12° | 23°°C 0.2 mm 20% 12 mph 79 % 1025 mb 0 mm/h
Mo. Juni 16 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 6 mph 87 % 1028 mb 0 mm/h
Di. Juni 17 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Mi. Juni 18 10:00 pm
Wetter-Symbol
17° | 27°°C 0 mm 0% 10 mph 80 % 1026 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 18°°C 0 mm 0% 8 mph 64 % 1018 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 17°°C 0 mm 0% 6 mph 69 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 6 mph 79 % 1019 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 75 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 10 mph 64 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
21° | 21°°C 0.2 mm 20% 10 mph 52 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 12 mph 36 % 1022 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 10 mph 52 % 1023 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,466.22
-0.77%
Ethereum(ETH)
€2,168.36
-1.21%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.84
-0.47%
Solana(SOL)
€123.41
-2.19%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.152440
-0.56%
Shiba Inu(SHIB)
€0.000010
0.01%
Pepe(PEPE)
€0.000010
-1.33%
Nach oben scrollen