In a recent attack against a US-based think tank, Iranian cyberespionage group Charming Kitten was observed porting a PowerShell backdoor to macOS, Proofpoint reports.
The attack started in mid-May with a lure sent to the public media contact for a nuclear security expert at the think tank, requesting feedback on a project and permissions to send a draft for review.
In the follow-up email, the cyberspies sent a malicious link directing the recipient to a password-encrypted archive file hosted on Dropbox, which contained a link (LNK) file meant to start an infection chain leading to the deployment of a new PowerShell backdoor.
Dubbed GorjolEcho by Proofpoint, the backdoor would establish persistence and then display a decoy PDF to the recipient, while in the background it begins exfiltrating information to the command-and-control (C&C) server.
A week later, Charming Kitten sent an email message containing a password-protected ZIP file that would trigger a macOS-tailored infection chain leading to the deployment of a bash script that establishes a persistent backdoor on the system.
Dubbed NokNok, the script “is almost certainly a port or evolution of the aforementioned GorjolEcho and is intended to serve as an initial foothold” within the victim’s system, Proofpoint says.
NokNok, which contains four modules, can collect credentials from the infected machine, a list of all currently running processes, logs, system information, network information, and software information, and then send the data, encrypted, to the C&C server.
According to Proofpoint, both GorjolEcho and NokNok likely support additional modules that expand their functionality.
The new attack, the cybersecurity firm notes, differs from previously observed Charming Kitten campaigns that typically relied on VBA macros and remote template injection for malware delivery.
However, Proofpoint attributes the attack to the Iranian group with high confidence, based on code similarities between GorjolEcho and NokNok and malware previously attributed to the group, including GhostEcho, CharmPower, and MacDownloader.
Also tracked as APT42, Mint Sandstorm (formerly Phosphorus), NewsBeef, Newscaster, TA453, and Yellow Garuda, Charming Kitten is believed to be operating on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC).
Previously, the group was seen targeting activists, government organizations, journalists, and other entities, and also engaging in financially-motivated ransomware attacks.
“TA453 continues to significantly adapt its infection chains to complicate detection efforts and conduct cyber espionage operations against its targets of interest. TA453’s willingness to port malware to Mach-O demonstrates how much effort the threat actor is willing to put into pursuing its targets,” Proofpoint notes.
Related: Microsoft: Iranian APTs Exploiting Recent PaperCut Vulnerability
Related: Microsoft: Iranian Hackers Moved From Recon to Targeting US Critical Infrastructure
Related: Iranian Hackers Using New PowerShell Backdoor Linked to Memento Ransomware

More from Ionut Arghire
- Generative AI Startup Nexusflow Raises $10.6 Million
- Researchers Extract Sounds From Still Images on Smartphone Cameras
- Hackers Set Sights on Apache NiFi Flaw That Exposes Many Organizations to Attacks
- Cloudflare Users Exposed to Attacks Launched From Within Cloudflare: Researchers
- FBI Warns Organizations of Dual Ransomware, Wiper Attacks
- Lumu Raises $30 Million for Threat Detection and Response Platform
- Cisco Warns of IOS Software Zero-Day Exploitation Attempts
- Russian Zero-Day Acquisition Firm Offers $20 Million for Android, iOS Exploits
Latest News
- Bankrupt IronNet Shuts Down Operations
- AWS Using MadPot Decoy System to Disrupt APTs, Botnets
- Generative AI Startup Nexusflow Raises $10.6 Million
- In Other News: RSA Encryption Attack, Meta AI Privacy, ShinyHunters Hacker Guilty Plea
- Researchers Extract Sounds From Still Images on Smartphone Cameras
- National Security Agency is Starting an Artificial Intelligence Security Center
- CISA Warns of Old JBoss RichFaces Vulnerability Being Exploited in Attacks
- Hackers Set Sights on Apache NiFi Flaw That Exposes Many Organizations to Attacks
