Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Phishing

Targeted Phishing Campaign Leverages Death of Iranian General Qasem Suleimani

A targeted phishing campaign against government entities in Persian Gulf and Middle East countries was detected earlier this month. The campaign was using the heightened tension in the region following the killing of Iranian general Qasem Suleimani at a Baghdad airport, and used emails purporting to come from the Ministry of Foreign Affairs of the Kingdom of Bahrain, Saudi Arabia, and the United Arab Emirates.

A targeted phishing campaign against government entities in Persian Gulf and Middle East countries was detected earlier this month. The campaign was using the heightened tension in the region following the killing of Iranian general Qasem Suleimani at a Baghdad airport, and used emails purporting to come from the Ministry of Foreign Affairs of the Kingdom of Bahrain, Saudi Arabia, and the United Arab Emirates.

The campaign was detected and reported by researchers at Blue Hexagon, a firm that uses artificial intelligence (AI) techniques developed to detect malware hidden in images to detect malware hiding in traffic.

The campaign was delivered via a legitimate email marketing provider. The malware payloads were stored on Google Drive, and command and control communication was delivered from Twitter. The use of legitimate public services in malware attacks is a growing trend among attackers. It helps the attack fly under the radar of standard detection, helps to disguise the attackers (there is no domain C&C infrastructure that could overlap with other known attacks), and is easily dismantled and reassembled elsewhere in the event of discovery.

Qasem Suleimani used in targeting phishing attack

This is not an attack technique that has been associated with Iranian actors in the past, and is part of the reason that Blue Hexagon does not believe the campaign — despite the phishing lure — has any direct link to Iran. “Although attribution is difficult,” Irfan Asrar, head of cyber threat intelligence and operations at Blue Hexagon told SecurityWeek, “we can say with pretty high confidence that this attack is not coming out of Iran. It seems to be an attempt by eastern European actors to use the current situation to gain access to important government institutions, including embassies and government officials.”

The lure is based on the death of Qasem Suleimani and the subsequent tensions throughout the middle east region. The countries targeted can be called regional allies of the U.S.; and are exactly the countries that usually suffer from Iranian ‘revenge’ attacks against the U.S. The document attached to the emails shows images of Suleimani and Iran’s traditional ‘red flag of revenge’. These images and much of the text are blurred. The argument is that ‘you should expect revenge attacks from Iran, you should read this document for information from the ministry, and you need to enable Word functions to do so.’

However, if these functions are enabled, malicious payloads hosted on Google Drive are downloaded, including a backdoor/RAT. “Once enabled,” write the researchers, “a malicious macro embedded in a document that is downloaded will be executed to download an additional executable payload.” One of the downloads is a humorous cartoon involving Mr Bean (again, not something that would be normally be associated with an Iranian attacker) but containing an encrypted backdoor/RAT.

“If the number of payloads being downloaded seems confusing,” continue the researchers, “keep in mind that the more payloads that are dropped/downloaded, the more modular the attack; additionally, this makes analyzing and investigating the attack more complicated.”

The malicious code employed has some overlaps with known malware, but not enough to specify the malware or its authors.

Despite Blue Hexagon’s belief that Iran is not involved with the attack, it is worth noting that motivation for the campaign is difficult. The exclusion of Qatar from the targeted countries hints at a political motivation, and Iran is well known for using proxies — both physical and cyber — rather than direct involvement. Nevertheless, using proxies from Eastern Europe would be new and unusual.

Be that as it may, the attacks most likely came out of eastern Europe and were undertaken by a sophisticated group. “Definitely, these guys have experience,” Asrar told SecurityWeek. “They’ve done this before, given the quick turnaround. We believe the attacks started just after the first week of January (Soleimani was killed January 2, 2020). Around 14 January we started notifying the people who were impacted; but within days we began to see parts of the infrastructure being dismantled. It seems they wanted to get in, get information, and pull out. That alone implies that these people have done this before.”

But that’s the nature of this type of attack. Once the methodology is established, it can be taken down, moved, and put together in a new campaign very rapidly.

Related: Iran May Respond With Cyberattacks to Killing of Qassem Soleimani 

Related: How Will Iran Retaliate to Soleimani Killing? 

Related: U.S. Girds for Cyber Threats From Iran as Military Clash Fears Ebb 

Related: Threat Posed by Iran to Industrial Systems After Killing of Top General 

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this webinar to learn best practices that organizations can use to improve both their resilience to new threats and their response times to incidents.

Register

Join this live webinar as we explore the potential security threats that can arise when third parties are granted access to a sensitive data or systems.

Register

Expert Insights

Related Content

Phishing

The easiest way for a cyber-attacker to gain access to sensitive data is by compromising an end user’s identity and credentials. Things get even...

Nation-State

The North Korean APT tracked as TA444 is either moonlighting from its previous primary purpose, expanding its attack repertoire, or is being impersonated by...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Application Security

Password management firm LastPass says the hackers behind an August data breach stole a massive stash of customer data, including password vault data that...

Application Security

Microsoft on Tuesday pushed a major Windows update to address a security feature bypass already exploited in global ransomware attacks.The operating system update, released...

Phishing

The Single Most Important Part of Dealing with a Phishing Attack is Preparing for the Attack Before it Actually Happens.

Cybercrime

Reddit says its systems were hacked following a sophisticated phishing attack aimed at employees.

Application Security

Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to...