{"id":58294,"date":"2021-10-07T11:33:48","date_gmt":"2021-10-07T10:33:48","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=58294"},"modified":"2021-10-20T10:28:50","modified_gmt":"2021-10-20T09:28:50","slug":"cybereason-exposes-iranian-state-sponsored-cyber-espionage-campaign","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2021\/10\/07\/cybereason-exposes-iranian-state-sponsored-cyber-espionage-campaign\/","title":{"rendered":"Cybereason exposes Iranian state-sponsored cyber-espionage campaign"},"content":{"rendered":"\n<p>Cybereason, a leader in operation-centric attack protection, has published a new threat intelligence report that unmasks a cyber-espionage operation targeting global aerospace and telecommunications companies.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2021\/06\/Lior-Div-CEO-Cybereason-lowres-2-w.jpg\" alt=\"\" class=\"wp-image-7407\" width=\"235\" height=\"302\"\/><figcaption><strong>Lior Div, Cybereason CEO and Co-founder<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n<p>The report identifies a newly discovered Iranian threat actor behind the attacks dubbed&nbsp;MalKamak&nbsp;that has been operating since at least 2018 and remained unknown until recently.<\/p>\n\n\n\n<p>In addition, the still-active campaign leverages a very sophisticated and previously undiscovered Remote Access Trojan (RAT) dubbed&nbsp;ShellClient&nbsp;that evades antivirus tools and other security apparatus and abuses the public cloud service Dropbox for command and control (C2).&nbsp;<\/p>\n\n\n\n<p>The report, titled&nbsp;<a href=\"https:\/\/www.cybereason.com\/blog\/operation-ghostshell-novel-rat-targets-global-aerospace-and-telecoms-firms\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Operation GhostShell: Novel RAT Targets Global Aerospace and Telecoms Firms<\/em><\/a>,&nbsp;details the stealthy attacks against companies in the Middle East, United States, Europe and Russia.<\/p>\n\n\n\n<p>\u201cThe <em>Operation GhostShell<\/em> <em>Report<\/em> revealed a complex RAT capable of evading detection since as early as 2018, and the recent <em>DeadRinger<\/em> <em>Report<\/em> also uncovered a similarly evasive threat from as early as 2017, which tells us a lot about how advanced attackers are continuously defeating security solutions,\u201d said Cybereason CEO and Co-founder, Lior Div.<\/p>\n\n\n\n<p>\u201cLayering on more tools to produce even more alerts that overwhelm defenders is not helping us stop sophisticated attacks, which is why Cybereason takes an operation-centric approach that detects based on very subtle chains of behavior where the adversary\u2019s own actions work against them to reveal the attack at the earliest stages.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybereason, a leader in operation-centric attack protection, has published a new threat intelligence report that unmasks a cyber-espionage operation targeting global aerospace and telecommunications companies. The report identifies a newly discovered Iranian threat actor behind the attacks dubbed&nbsp;MalKamak&nbsp;that has been operating since at least 2018 and remained unknown until recently. In addition, the still-active campaign [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":58755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,14,248],"tags":[192,8367,8927,16516,494],"class_list":["post-58294","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-more-news","category-telecom","tag-aerospace","tag-cyber-espionage","tag-cybereason","tag-lior-div","tag-telecommunications"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/58294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=58294"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/58294\/revisions"}],"predecessor-version":[{"id":58754,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/58294\/revisions\/58754"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/58755"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=58294"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=58294"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=58294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}