#apt34 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #apt34, aggregated by home.social.
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
Targeted Iranian Attacks Against Iraqi Government Infrastructure
#APT34 #Veaty #Spearal
https://research.checkpoint.com/2024/iranian-malware-attacks-iraqi-government/ -
This malware empowers attackers to exercise complete control over information stored on compromised devices within the network.
-
This malware empowers attackers to exercise complete control over information stored on compromised devices within the network.
-
The exact targets of these attacks are not yet known, but the use of decoys suggests that at least one of the organizations being targeted is located in Saudi Arabia.
#Cybersecurity #Iran #HackerGroup #Malware #APT34 #Menorah #OilRig
-
The exact targets of these attacks are not yet known, but the use of decoys suggests that at least one of the organizations being targeted is located in Saudi Arabia.
#Cybersecurity #Iran #HackerGroup #Malware #APT34 #Menorah #OilRig
-
Their modus operandi involves spear-phishing techniques that ultimately result in the deployment of various backdoors.
-
Their modus operandi involves spear-phishing techniques that ultimately result in the deployment of various backdoors.
-
Pick your poison: The potential Iranian responses to US drone strike - Enlarge / TEHRAN, IRAN - (ARCHIVE): A file photo dated September 18, 2016 shows Iranian Revolutiona... more: https://arstechnica.com/?p=1638517 #iranrevolutionaryguardcorps #hellfiremissile #qudsforce #biz&it #policy #oilrig #apt33 #apt34 #iraq #isis
-
Researchers think nation-sponsored hackers attacked rival espionage group - Enlarge
If nation-sponsored hacking was baseball, the Russian-speaking group called Turla would ... more: https://arstechnica.com/?p=1524749 #espionage #waterbug #crambus #hacking #biz&it #oilrig #apt34 #turla -
Always interesting to see APTs using old-school GUI tools like these. It tells you that they probably have less skilled operators (military?) using the tools #APT34 #leak #Jason https://t.co/sKQwtZVeDh
-
My thoughts about the recent #APT34 leaks https://blog.0day.rocks/hacking-back-and-influence-operations-85cd52c1e933