home.social

#apt34 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #apt34, aggregated by home.social.

fetched live
  1. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  2. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  3. The exact targets of these attacks are not yet known, but the use of decoys suggests that at least one of the organizations being targeted is located in Saudi Arabia.

    #Cybersecurity #Iran #HackerGroup #Malware #APT34 #Menorah #OilRig

    cybersec84.wordpress.com/2023/

  4. The exact targets of these attacks are not yet known, but the use of decoys suggests that at least one of the organizations being targeted is located in Saudi Arabia.

    #Cybersecurity #Iran #HackerGroup #Malware #APT34 #Menorah #OilRig

    cybersec84.wordpress.com/2023/

  5. Pick your poison: The potential Iranian responses to US drone strike - Enlarge / TEHRAN, IRAN - (ARCHIVE): A file photo dated September 18, 2016 shows Iranian Revolutiona... more: arstechnica.com/?p=1638517 #iranrevolutionaryguardcorps #hellfiremissile #qudsforce #biz&it #policy #oilrig #apt33 #apt34 #iraq #isis

  6. Researchers think nation-sponsored hackers attacked rival espionage group - Enlarge
    If nation-sponsored hacking was baseball, the Russian-speaking group called Turla would ... more: arstechnica.com/?p=1524749 #espionage #waterbug #crambus #hacking #biz&it #oilrig #apt34 #turla

  7. Always interesting to see APTs using old-school GUI tools like these. It tells you that they probably have less skilled operators (military?) using the tools #APT34 #leak #Jason t.co/sKQwtZVeDh