Malware & Threats

Iranian Cyberspies Target US-Based Think Tank With New macOS Malware

In May 2023, Iran-linked cyberespionage group Charming Kitten targeted a US-based think tank with new macOS malware.

In May 2023, Iran-linked cyberespionage group Charming Kitten targeted a US-based think tank with new macOS malware.

In a recent attack against a US-based think tank, Iranian cyberespionage group Charming Kitten was observed porting a PowerShell backdoor to macOS, Proofpoint reports.

The attack started in mid-May with a lure sent to the public media contact for a nuclear security expert at the think tank, requesting feedback on a project and permissions to send a draft for review.

In the follow-up email, the cyberspies sent a malicious link directing the recipient to a password-encrypted archive file hosted on Dropbox, which contained a link (LNK) file meant to start an infection chain leading to the deployment of a new PowerShell backdoor.

Dubbed GorjolEcho by Proofpoint, the backdoor would establish persistence and then display a decoy PDF to the recipient, while in the background it begins exfiltrating information to the command-and-control (C&C) server.

A week later, Charming Kitten sent an email message containing a password-protected ZIP file that would trigger a macOS-tailored infection chain leading to the deployment of a bash script that establishes a persistent backdoor on the system.

Dubbed NokNok, the script “is almost certainly a port or evolution of the aforementioned GorjolEcho and is intended to serve as an initial foothold” within the victim’s system, Proofpoint says.

Advertisement. Scroll to continue reading.

NokNok, which contains four modules, can collect credentials from the infected machine, a list of all currently running processes, logs, system information, network information, and software information, and then send the data, encrypted, to the C&C server.

According to Proofpoint, both GorjolEcho and NokNok likely support additional modules that expand their functionality.

The new attack, the cybersecurity firm notes, differs from previously observed Charming Kitten campaigns that typically relied on VBA macros and remote template injection for malware delivery.

However, Proofpoint attributes the attack to the Iranian group with high confidence, based on code similarities between GorjolEcho and NokNok and malware previously attributed to the group, including GhostEcho, CharmPower, and MacDownloader.

Also tracked as APT42, Mint Sandstorm (formerly Phosphorus), NewsBeef, Newscaster, TA453, and Yellow Garuda, Charming Kitten is believed to be operating on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC).

Previously, the group was seen targeting activists, government organizations, journalists, and other entities, and also engaging in financially-motivated ransomware attacks.

“TA453 continues to significantly adapt its infection chains to complicate detection efforts and conduct cyber espionage operations against its targets of interest. TA453’s willingness to port malware to Mach-O demonstrates how much effort the threat actor is willing to put into pursuing its targets,” Proofpoint notes.

Related: Microsoft: Iranian APTs Exploiting Recent PaperCut Vulnerability

Related: Microsoft: Iranian Hackers Moved From Recon to Targeting US Critical Infrastructure

Related: Iranian Hackers Using New PowerShell Backdoor Linked to Memento Ransomware

Related Content

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Malware & Threats

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

ICS/OT

The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.

Cyberwarfare

The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.

ICS/OT

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.

ICS/OT

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.

Malware & Threats

Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out.

ICS/OT

An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version