Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Suspect Iranian hackers used compromised E -mail to Indian firm for the purpose of the UAE aviation sector
Global Security

Suspect Iranian hackers used compromised E -mail to Indian firm for the purpose of the UAE aviation sector

AdminBy AdminMarch 4, 2025No Comments3 Mins Read
Target UAE Aviation Sector
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


04 March 2025Red LakshmananCyber ​​-bue / malicious software

UAE target aviation sector

Hunters pay attention to a new high -level phishing campaign that nominated “less than five” legal entities in the United Arab Emirates (UAE) to deliver the previously unregistered back Galan Sosan.

According to Profpoint, which discovered it in late October 2024, was specially aimed at aviation and satellite communication organizations. Unk_craftcamel.

The characteristic aspect of the attack chain is that the opponent took advantage of his access to a compromised email account owned by the Indian Electronics Company, indicates electronic electronic information to send phishing messages. It is said that the legal entity was on trusted business relations with all the goals, while the baits, taking into account each of them.

Cybersecurity

“UNK_CRAFTYCamel used a disturbed Indian Electronics Company to focus on less than five organizations in the United Arab Emirates with a harmful postal file that used multiple Polyglot -folk To eventually set a custom posterior report Share with Hacker News.

The e -mails contained the URL, indicating a dummy domain, which is masked as an Indian company (“Indicelectronics (.) Net”, which conducted an archive of ZIP, which included the XLS file and two PDF files.

But in reality, the XLS file was a Windows (LNK) shortcut using a double extension to go as a Microsoft Excel document. On the other hand, two PDF files were polyglots: the one that was added using the HTML (HTA) file and the other with the ZIP archive is added to it.

It also meant that both PDF files can be interpreted as two different valid formats depending on how they are disassembled using programs such as file researchers, command line tools and browsers.

The attack sequence analyzed by ProfofPoint entails the use of the LNK file to run cmd.exe, and then using Mshta.exe to run PDF/HTA Polyglot file, which will lead the hta script, which in turn contains the instructions for steaming the content of the archive, which is in the second pdf.

UAE target aviation sector

One of the files in the second PDF is a quick access file (URL), which is responsible for booting the binary that is further looking for an image file that ultimately Xored With the line “234567890abcdef” to decrypt and run a dll backdoor called Sosano.

The implant written in Golang carries limited functionality to establish contact with the team server and control (C2) and wait for further teams-

  • SosanoTo get the current directory or change the work directory
  • ato list the contents of the current directory
  • MondayTo download and run an unknown useful load at the next stage
  • RyanDelete or delete the directory
  • Lunnato execute the shell command

ProfofPoint noted that TradeCraft, demonstrated by Unk_craftyCamel, does not intersect with any famous actor and threat group.

Cybersecurity

“Our analysis suggests that this company is probably the work of the Iranian enemy, perhaps related to the Islamic Revolutionary Corps of the Guard (IRGC),” said Joshua Miller, threatening PROFPOINT, Hacker News. “The target sectors are crucial for both economic stability and national security, making them valuable exploration goals in a broader geopolitical landscape.”

“This low volume, a highly focused phishing company used several methods of aggravation, along with a trusted third compromise to orientation to aviation, satellite communication and critical transport infrastructure in the UAE, it demonstrates the length to which the state actors will go to the detection and execution of their mandates.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.