{"id":9767,"date":"2021-10-07T11:33:48","date_gmt":"2021-10-07T10:33:48","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=9767"},"modified":"2021-10-20T10:28:50","modified_gmt":"2021-10-20T09:28:50","slug":"cybereason-exposes-iranian-state-sponsored-cyber-espionage-campaign","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2021\/10\/07\/cybereason-exposes-iranian-state-sponsored-cyber-espionage-campaign\/","title":{"rendered":"Cybereason exposes Iranian state-sponsored cyber-espionage campaign"},"content":{"rendered":"\n<p>Cybereason, a leader in operation-centric attack protection, has published a new threat intelligence report that unmasks a cyber-espionage operation targeting global aerospace and telecommunications companies.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2021\/06\/Lior-Div-CEO-Cybereason-lowres-2-w.jpg\" alt=\"\" class=\"wp-image-7407\" width=\"235\" height=\"302\" srcset=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2021\/06\/Lior-Div-CEO-Cybereason-lowres-2-w.jpg 450w, https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2021\/06\/Lior-Div-CEO-Cybereason-lowres-2-w-234x300.jpg 234w\" sizes=\"auto, (max-width: 235px) 100vw, 235px\" \/><figcaption><strong>Lior Div, Cybereason CEO and Co-founder<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n<p>The report identifies a newly discovered Iranian threat actor behind the attacks dubbed&nbsp;MalKamak&nbsp;that has been operating since at least 2018 and remained unknown until recently.<\/p>\n\n\n\n<p>In addition, the still-active campaign leverages a very sophisticated and previously undiscovered Remote Access Trojan (RAT) dubbed&nbsp;ShellClient&nbsp;that evades antivirus tools and other security apparatus and abuses the public cloud service Dropbox for command and control (C2).&nbsp;<\/p>\n\n\n\n<p>The report, titled&nbsp;<a href=\"https:\/\/www.cybereason.com\/blog\/operation-ghostshell-novel-rat-targets-global-aerospace-and-telecoms-firms\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Operation GhostShell: Novel RAT Targets Global Aerospace and Telecoms Firms<\/em><\/a>,&nbsp;details the stealthy attacks against companies in the Middle East, United States, Europe and Russia.<\/p>\n\n\n\n<p>\u201cThe <em>Operation GhostShell<\/em> <em>Report<\/em> revealed a complex RAT capable of evading detection since as early as 2018, and the recent <em>DeadRinger<\/em> <em>Report<\/em> also uncovered a similarly evasive threat from as early as 2017, which tells us a lot about how advanced attackers are continuously defeating security solutions,\u201d said Cybereason CEO and Co-founder, Lior Div.<\/p>\n\n\n\n<p>\u201cLayering on more tools to produce even more alerts that overwhelm defenders is not helping us stop sophisticated attacks, which is why Cybereason takes an operation-centric approach that detects based on very subtle chains of behavior where the adversary\u2019s own actions work against them to reveal the attack at the earliest stages.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybereason, a leader in operation-centric attack protection, has published a new threat intelligence report that unmasks a cyber-espionage operation targeting global aerospace and telecommunications companies. The report identifies a newly discovered Iranian threat actor behind the attacks dubbed&nbsp;MalKamak&nbsp;that has been operating since at least 2018 and remained unknown until recently. In addition, the still-active campaign [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":9768,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17,511,34,41,514],"tags":[2453,2452,351,2454,223],"class_list":["post-9767","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology-newsletter","category-more-news","category-telecom","category-used","tag-aerospace","tag-cyber-espionage","tag-cybereason","tag-lior-div","tag-telecommunications"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/9767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=9767"}],"version-history":[{"count":9,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/9767\/revisions"}],"predecessor-version":[{"id":9940,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/9767\/revisions\/9940"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/9768"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=9767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=9767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=9767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}