Search/Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
Story

Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign

Microsoft on Thursday disclosed that it revoked more than 200 certificates used by a threat actor it tracks as Vanilla Tempest to fraudulently sign malicious binaries in ransomware attacks. The certificates were "used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware," the Microsoft Threat Intelligence team said in a post shared on X. The tech giant said it disrupted the activity earlier this month after it was detected in late September 2025. In addition to revoking the certificates, its security solutions have been updated to flag the signatures associated with the fake setup files, Oyster backdoor, and Rhysida ransomware. Vanilla Tempest (formerly Storm-0832) is the name given to a financially motivated threat actor also called Vice…

CVEs
0
Highest CVSS
In KEV
0
Sources
3
Connections
11 relationships
Microsoft blocca Vanilla Tempest: Falsi installer di Teams diffondevano ransomware Rhysida
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comOct 17, 2025extracted
Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
Microsoft on Thursday disclosed that it revoked more than 200 certificates used by a threat actor it tracks as Vanilla Tempest to fraudulently sign malicious binaries in ransomware attacks. The certificates were "used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware," the Microsoft Threat Intelligence team said in a post shared on X. The tech giant said it disrupted the activity earlier this month after it was detected in late September 2025. In addition to revoking the certificates, its security solutions have been updated to flag the signatures associated with the fake setup files, Oyster backdoor, and Rhysida ransomware. Vanilla Tempest (formerly Storm-0832) is the name given to a financially motivated threat actor also called Vice Society and Vice Spider that's assessed to be active since at least July 2022, delivering various ransomware strains such as BlackCat, Quantum Locker, Zeppelin, and Rhysida over the years. Oyster (aka Broomstick and CleanUpLoader), on the other hand, is a backdoor that's often distributed via trojanized installers for popular software such as Google Chrome and Microsoft Teams using bogus websites that users stumble upon when searching for the programs on Google and Bing. "In this campaign, Vanilla Tempest used fake MSTeamsSetup.exe files hosted on malicious domains mimicking Microsoft Teams, for example, teams-download[.]buzz, teams-install[.]run, or teams-download[.]top," Microsoft said. "Users are likely directed to malicious download sites using search engine optimization (SEO) poisoning." To sign these installers and other post-compromise tools, the threat actor is said to have used Trusted Signing, as well as SSL[.]com, DigiCert, and GlobalSign code signing services. Details of the campaign were first disclosed by Blackpoint Cyber last month, highlighting how users searching for Teams online were redirected to bogus download pages, where they were offered a malicious MSTeamsSetup.exe instead of the legitimate client. "This activity highlights the continued abuse of SEO poisoning and malicious advertisements to deliver commodity backdoors under the guise of trusted software," the company said. "Threat actors are exploiting user trust in search results and well-known brands to gain initial access." To mitigate such risks, it's advised to download software only from verified sources and avoid clicking on suspicious links served via search engine ads. Update Expel, in a follow-up analysis published on October 31, 2025, disclosed details of an ongoing malvertising campaign that's delivering the Oyster loader. The activity, observed since June 2025, is a continuation of a previous wave that ran from May to September 2024. "Threat actors buy Bing search engine advertisements to direct users to convincing-looking, but malicious landing pages," security researcher Aaron Walton said. "These search engine ads put links to the download right in front of potential victims." The malvertising efforts are designed to direct users searching for popular software programs like Microsoft Teams, PuTTY, and Zoom to fake websites that drop counterfeit versions containing the loader. To achieve low detection rates, the loaders are compressed and obfuscated using a packer and use code-signing certificates to give the executables an illusion of trust. Expel said it found 47 unique certificates used to sign Oyster across the two campaign waves, and that the threat actors are also using the Latrodectus malware to get initial access to networks. This is evidenced by the fact that the same code-signing certificate from Art en Code B.V. has been used to sign both malware in mid-September 2025. "In the majority of situations, Rhysida has smartly avoided using the same certificate across campaigns," Walton said. "However, this activity highlights their involvement with both campaigns." (The story was updated after publication on November 3, 2025, with additional insights from Expel.)
thehackernews.comOct 17, 2025extracted
Microsoft disrupts ransomware attacks targeting Teams users
Microsoft has disrupted a wave of Rhysida ransomware attacks in early October by revoking over 200 certificates used to sign malicious Teams installers. Vanilla Tempest, the threat group behind the attacks, used domains that mimic Microsoft Teams, such as teams-install[.]top, teams-download[.]buzz, teams-download[.]top, and teams-install[.]run, to distribute fake MSTeamsSetup.exe files that infected victims with the Oyster backdoor. These attacks were part of a late September malvertising campaign that used search engine ads and SEO poisoning to push fake Microsoft Teams installers that backdoored Windows devices with Oyster malware (also known as Broomstick and CleanUpLoader). The ads and the domains led to websites that impersonated the Microsoft Teams download site. Clicking the prominently displayed download link downloads a file named "MSTeamsSetup.exe," the same filename used by the official Teams installer. Upon execution, the malicious Teams installers launched a loader that deployed the signed Oyster malware, granting the threat actors remote access to the infected systems and allowing them to steal files, execute commands, and drop additional malicious payloads. Vanilla Tempest has been using the Oyster backdoor since June 2025, leveraging Trusted Signing alongside code signing services from SSL.com, DigiCert, and GlobalSign starting in September 2025. This malware, first spotted in mid-2023, was also used in previous Rhysida attacks to breach corporate networks and is commonly spread and WinSCP. "Vanilla Tempest, tracked by other security vendors as VICE SPIDER and Vice Society, is a financially motivated actor that focuses on deploying ransomware and exfiltrating data for extortion," Microsoft said. "The threat actor has used various ransomware payloads, including BlackCat, Quantum Locker, and Zeppelin, but more recently has been primarily deploying Rhysida ransomware." Active since at least June 2021, Vanilla Tempest has frequently attacked organizations in the education, healthcare, IT, and manufacturing sectors. While active as Vice Society, the threat actor was known to use multiple ransomware strains, including Hello Kitty/Five Hands and Zeppelin ransomware. Three years ago, in September 2022, the FBI and CISA issued a joint advisory warning that Vice Society disproportionately targeted the U.S. education sector after the cybercrime gang breached Los Angeles Unified (LAUSD), the second-largest school district in the United States. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 16, 2025extracted
Related Stories
4
US Government Warns of Wide-Ranging Interlock Attacks
The US government has warned businesses and critical infrastructure organizations to stay vigilant against wide-ranging attacks from the Interlock ransomware gang. The joint advisory from four government agencies including the FBI and the Department of Health and Human Services (HHS), highlighted the novel initial access techniques used by the cybercrime group. This includes “drive-by-download” and ClickFix social engineering techniques. The group, first identified in late September 2024, has been observed targeting various business, critical infrastructure and other organizations in North America and Europe. High-profile incidents attributed to Interlock in 2025 include Kettering Health, a major healthcare provider in western Ohio, US, and Scottish local authority West Lothian council. Its favored tactic is double extortion, in which threat actors exfiltrate data as well as encrypt it, increasing the pressure on victims to pay a ransom demand. The ransomware encryptors deployed are designed for both Windows and Linux operating systems. “These actors are opportunistic and financially motivated in nature and employ tactics to infiltrate and disrupt the victim’s ability to provide their essential services,” the advisory, published on July 22, warned. “Uncommon” Method for Initial Access The FBI has observed Interlock using a technique called drive-by-download to obtain initial access, which was described as an “uncommon method among ransomware groups.” This technique involves the compromise of legitimate websites, which automatically installs malware onto the victim’s device upon being visited. Interlock actors have also used the ClickFix social engineering technique to gain initial access. This tactic involves the use of a fake error or verification message to manipulate victims into copying and pasting a malicious script and then running it. Post-compromise, affiliates deploy various methods for discovery, credential access and lateral movement. A PowerShell script executes a series of commands designed to gather information on victim machines. Once command and control (C2) is established, a series of PowerShell commands are used to download a credential stealer and keylogger binary. These tools collect various information to help facilitate access between systems, including login information and users’ keystrokes. Remote desktop protocol (RDP) is also leveraged to facilitate lateral movement. Data is then exfiltrated via AzCopy, a legitimate tool used to copy files, and various file transfer tools, including WinSCP. Following exfiltration, Interlock launches ransomware encryptors. Encrypted files are appended with a ransom note titled !README!.txt. Interlock affiliates do not leave an initial ransom demand or payment instructions in this note, instead each victim is provided with a unique code and instructions to contact the ransomware actors via a .onion URL. When contact is made, victims are instructed to make ransom payments in Bitcoin to cryptocurrency wallet addresses provided by the actors. The actors also threaten to publish the victim’s exfiltrated data to their leak site on the Tor network unless the victim pays the ransom demand. “The actors have previously followed through on this threat,” the agencies noted. How to Defend Against Interlock Attacks The advisory set out a range of recommendations for organizations to protect against the techniques used by Interlock. These include: Reduce the risk of drive-by-download by implementing domain name system (DNS) to block users from accessing malicious sites Implement web access firewalls to mitigate and prevent unknown commands or process injection from malicious domains or websites Implement additional email security measures, including disabling hyperlinks in received emails Require all accounts with passwords to comply with National Institute of Standards and Technology (NIST) password guidance and implement multi-factor authentication (MFA) for all services Filter network traffic by preventing unknown or untrusted origins from accessing remote services on internal systems Maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented and secure location Segment networks to prevent the spread of ransomware
4 shared
Jul 25, 2025
Financial Services Could Be Next in Line for ShinyHunters
An ongoing data extortion campaign targeting Salesforce customers may soon turn its attention to financial services and technology service providers, as ShinyHunters and Scattered Spider appear to be working hand in hand, new findings show. "This latest wave of ShinyHunters-attributed attacks reveals a dramatic shift in tactics, moving beyond the group's previous credential theft and database exploitation," ReliaQuest said in a report shared with The Hacker News. These include the use of adoption of tactics that mirror those of Scattered Spider, such as highly-targeted vishing (aka voice phishing) and social engineering attacks, leveraging apps that masquerade as legitimate tools, employing Okta-themed phishing pages to trick victims into entering credentials during vishing, and VPN obfuscation for data exfiltration. ShinyHunters, which first emerged in 2020, is a financially motivated threat group that has orchestrated a series of data breaches targeting major corporations and monetizing them on cybercrime forums like RaidForums and BreachForums. Interestingly, the ShinyHunters persona has been a key participant in these platforms both as a contributor and administrator. "The ShinyHunters persona partnered with Baphomet to relaunch the second instance of BreachForums (v2) in June 2023 and later launched the June 2025 instance (v4) alone," Sophos noted in a recent report. "The interim version (v3) abruptly disappeared in April 2025, and the cause is unclear." While the relaunch of the forum was short-lived and the bulletin board went offline around June 9, the threat actor has since been linked to attacks targeting Salesforce instances globally, a cluster of extortion-related activity that Google is tracking under the moniker UNC6240. Coinciding with these developments was the arrest of four individuals suspected of running BreachForums, including ShinyHunters, by French law enforcement authorities. However, the threat actor told DataBreaches.Net that "France rushed to make FALSE, INACCURATE arrests," raising the possibility that an "associate" member may have been caught. And that's not all. On August 8, a new Telegram channel conflating ShinyHunters, Scattered Spider, and LAPSUS$ called "scattered lapsu$ hunters" emerged, with the channel members also claiming to be developing a ransomware-as-a-service solution called ShinySp1d3r that they said will rival LockBit and DragonForce. Three days later, the channel was banned and removed by Telegram. Both Scattered Spider and LAPSUS$ have ties to a broader, nebulous collective dubbed The Com, a notorious network of experienced English-speaking cybercriminals that's known to engage in a wide range of malicious activities, including SIM swapping, extortion, and physical crime. "Scattered LAPSUS$ Hunters represents a new phase in cyber extortion where clout and chaos are as much the objectives as money," FalconFeeds said. "Their connection to known entities like Scattered Spider and ShinyHunters indicates this is less a “new” group than a rebranding and coalescence of existing threat actors responding to recent law enforcement heat." ReliaQuest said it has identified a coordinated set of ticket-themed phishing domains and Salesforce credential harvesting pages that are likely created for similar campaigns targeting Salesforce that are aimed at high-profile companies across various industry verticals. These domains, the company said, were registered using infrastructure typically associated with phishing kits commonly used to host single sign-on (SSO) login pages -- a hallmark of Scattered Spider's attacks impersonating Okta sign-in pages. Furthermore, an analysis of over 700 domains registered in 2025 that matched Scattered Spider phishing patterns has revealed that domain registrations targeting financial companies have increased by 12% since July 2025, while targeting of technology firms has decreased by 5%, suggesting that banks, insurance companies and financial services could be next in line. The tactical overlaps aside, that the two groups may be collaborating is borne out by the fact that they have targeted the same sectors (i.e., retail, insurance, and aviation) around the same time. "Supporting this theory is evidence such as the appearance of a BreachForums' user with the alias 'Sp1d3rHunters,' who was linked to a past ShinyHunters breach, as well as overlapping domain registration patterns," researchers Kimberley Bromley and Ivan Righi said, adding the account was created in May 2024. "If these connections are legitimate, they suggest that collaboration or overlap between ShinyHunters and Scattered Spider may have been ongoing for more than a year. The synchronized timing and similar targeting of these previous attacks strongly support the likelihood of coordinated efforts between the two groups." Update The threat actor collective ShinyHunters has announced that BreachForums has been commandeered by international law enforcement agencies, and that the site has been turned into a honeypot. "The platform is currently being operated by French law enforcement agencies, including the BL2C, in coordination with the United States Department of Justice (DoJ) and the Federal Bureau of Investigation (FBI)," ShinyHunters claimed, adding the accounts "Hollow," "ShinyHunters" are compromised, and that the account "N/A" has been taken over by a federal agent. "Law enforcement never figured it out but I am here to confirm ShinyHunters alt accounts were Anastasia and Hollow. Anastasia and Hollow administrator accounts were always controlled by one person, me, ShinyHunters." ShinyHunters' alleged leader, Shiny, also had a word of caution: "If BreachForums remains online following this notice, it is operating as a honeypot under the control of multiple international law enforcement agencies. BreachForums will not be returning under legitimate operation. Any reappearance of the site should be regarded as a law enforcement trap."
3 shared
Aug 12, 2025
PhantomCaptcha ClickFix attack targets Ukraine war relief orgs
A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for the war relief effort in Ukraine, including the International Committee of the Red Cross, UNICEF, and various NGOs. Dubbed PhantomCaptcha, the one-day campaign attempted to trick victims into running commands used in ClickFix attacks, disguised as Cloudflare CAPTCHA verification prompts, to install a WebSocket Remote Access Trojan (RAT). SentinelLABS, the threat research division at SentinelOne, says that the campaign started and ended on October 8, and that the attacker spent significant time and effort to set up the necessary infrastructure, as some domains used in the operation were registered at the end of March. "I am not a robot" ClickFix attacks The attacks started with emails impersonating the Ukrainian President’s Office, carrying malicious PDF attachments that linked to a domain impersonating the Zoom (zoomconference[.]app) communication platform. When clicking on the fake Zoom conference link, visitors saw an automated browser check process before redirecting to the communication platform. During this stage, a client identifier is generated and passed to the attacker's server over a Websocket connection. "If the WebSocket server responded with a matching identifier, the victim’s browser would redirect to a legitimate, password-protected Zoom meeting," SentinelLABS' analysis showed. According to the researchers, this path likely led to the threat actor engaging in live social engineering calls with the victim. If the client ID did not match, visitors had to pass another security check and prove that they were real people and not robots. They could complete the fake CAPTCHA verification by following instructions in Ukrainian that prompted them to press a button to copy a "token" and paste it in the Windows Command Prompt. What the copy/paste action did was to run a PowerShell command that downloaded and executed a malicious script (cptch) for delivering the second-stage payload, a reconnaissance and system-profiler utility. The tool collects system data like computer name, domain information, username, process ID, and system UUID, and sends it to the command-and-control (C2) server. The final payload is a lightweight WebSocket RAT capable of remote command execution and data exfiltration through base64-encoded JSON commands. The researchers found that the short-lived campaign was linked to a subsequent operation that targeted users in Lviv, Ukraine, with adult-themed Android APKs or cloud storage tools. These apps act as spyware, monitoring the victim’s real-time location, call logs, contact list, and images, exfiltrating them to the attackers. While SentinelLABS made no attribution for the "I am not a robot" ClickFix attacks, the researchers note that the WebSocket RAT was hosted on Russian infrastructure, and the adult-themed campaign may be related to Russia/Belarus source development. Additionally, a report from the Google Threat Intelligence Group (GTIG) yesterday describes a malicious "I am not a robot" captcha challenge used in attacks attributed to ColdRiver (a.k.a. Star Blizzard, UNC4057, Callisto), a threat group attributed to the Russian intelligence service (FSB). GTIG highlighted that the hackers were quick to operationalize new malware families after researchers had disclosed publicly older tools that ColdRiver deployed in cyberespionage activities. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
3 shared
Oct 22, 2025
FBI warns of Russian, Iranian cyber activity involving messaging platforms
Threat actors with ties to Iran successfully broke into the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation (FBI), and leaked a cache of photos and other documents to the internet. Handala Hack Team, which carried out the breach, said on its website that Patel "will now find his name among the list of successfully hacked victims." In a statement shared with Reuters, the FBI confirmed Patel's emails had been targeted, and noted necessary steps have been taken to "mitigate potential risks associated with this activity." The agency also said the published data was "historical in nature and involves no government information." The leak includes emails from 2010 and 2019 allegedly sent by Patel. Handala Hack is assessed to be a pro-Iranian, pro-Palestinian hacktivist persona adopted by Iran's Ministry of Intelligence and Security (MOIS). It's tracked by the cybersecurity community under the monikers Banished Kitten, Cobalt Mystique, Red Sandstorm, and Void Manticore, with the group also operating another persona called Homeland Justice to target Albanian entities since mid-2022. A third persona linked to the MOIS-affiliated adversary is Karma, which is said to have been likely completely replaced by Handala Hack since late 2023. Data gathered by StealthMole has revealed that Handala's online presence extends beyond messaging platforms and cybercrime forums like BreachForums to publicize its activities, maintaining a layered infrastructure that includes surface web domains, Tor-hosted services, and external file-hosting platforms such as MEGA. "Handala has consistently targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access," Check Point said in a report published this month. "Throughout the last months, we identified hundreds of logon and brute-force attempts against organizational VPN infrastructure linked to Handala-associated infrastructure." Attacks mounted by the proxy group are known to leverage RDP for lateral movement and initiate destructive operations by dropping wiper malware families such as Handala Wiper and Handala PowerShell Wiper via Group Policy logon scripts. Also used are legitimate disk encryption utilities like VeraCrypt to complicate recovery efforts. "Unlike financially motivated cybercriminal groups, Handala-associated activity has historically emphasized disruption, psychological impact, and geopolitical signaling," Flashpoint said. "Operations attributed to the persona frequently align with periods of heightened geopolitical tension and often target organizations with symbolic or strategic value." The development comes against the backdrop of the U.S.-Israel-Iran conflict, prompting Iran to go on a retaliatory cyber offensive against Western targets. Notably, Handala Hack claimed credit for crippling the networks of medical devices and services provider Stryker by deleting a huge trove of company data and wiping thousands of employee devices. The attack is the first confirmed destructive wiper operation targeting a U.S. Fortune 500 company. In an update issued on its website this week, Stryker said "the incident is contained," adding it "reacted quickly to not only regain access but to remove the unauthorized party from our environment" by dismantling the persistence mechanisms installed. The breach, it stated, was confined to its internal Microsoft environment. The threat actors have been found to use a malicious file to run commands that allowed them to conceal their actions. However, the file does not possess any capabilities to spread across the network, Stryker pointed out. Palo Alto Networks Unit 42 said the primary vector for recent destructive operations from Handala Hack likely involves the "exploitation of identity through phishing and administrative access through Microsoft Intune." Hudson Rock has found evidence that compromised credentials associated with Microsoft infrastructure obtained via infostealer malware may have been used to pull off the hack. In the wake of the breach, both Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA) have released guidance on hardening Windows domains and fortifying Intune to defend against similar attacks. This includes using the principle of least privilege, enforcing phishing-resistant multi-factor authentication (MFA), and enabling multi-admin approval in Intune for sensitive changes. Flashpoint has characterized the attack on Stryker as a dangerous shift in supply chain threats, as state-linked cyber activity targeting critical suppliers and logistics providers can have cascading impacts across the entire healthcare ecosystem. DoJ Takes Down Pro-Iranian Hacker Domains Handala Hack's leak of Patel's personal emails comes in response to a court-authorized operation that led to the seizure of four domains operated by MOIS since 2022 as part of an effort to disrupt its malicious activities in cyberspace. The U.S. government is also offering a $10 million reward for information on members of the group. The names of the seized domains are listed below - justicehomeland[.]org handala-hack[.]to karmabelow80[.]org handala-redwanted[.]to "The seized domains [...] were used by the MOIS in furtherance of attempted psychological operations targeting adversaries of the regime by claiming credit for hacking activity, posting sensitive data stolen during such hacks, and calling for the killing of journalists, regime dissidents, and Israeli persons," the U.S. Department of Justice (DoJ) said. This included the names and sensitive information of about 190 individuals associated with or employed by the Israeli Defense Force (IDF) and/or Israeli government, and 851 GB of confidential data from members of the Sanzer Hasidic Jewish community. In addition, an email address linked to the group ("handala_team@outlook[.]com") is alleged to have been used to send death threats to Iranian dissidents and journalists living in the U.S. and elsewhere. In a separate advisory, the FBI revealed that Handala Hack and other MOIS cyber actors have employed social engineering tactics to engage with prospective victims on social messaging applications to deliver Windows malware capable of enabling persistent remote access using a Telegram bot by masquerading the first-stage payload as commonly used programs like Pictory, KeePass, Telegram, or WhatsApp. Using Telegram (or other legitimate services) as C2 is a common tactic by threat actors to hide malicious activity among normal network traffic, and significantly reduce the likelihood of detection. Related malware artifacts found on compromised devices have revealed added capabilities to record audio and screen while a Zoom session was active. The attacks have targeted dissidents, opposition groups, and journalists, per the FBI. "MOIS cyber actors are responsible for using Telegram as a command-and-control (C2) infrastructure to push malware targeting Iranian dissidents, journalists opposed to Iran, and other opposition groups around the world," the bureau said. "This malware resulted in intelligence collection, data leaks, and reputational harm against the targeted parties." Handala Hack has since resurfaced on a different clearnet domain, "handala-team[.]to," where it described the domain seizures as "desperate attempts by the United States and its allies to silence the voice of Handala." The ongoing conflict has also prompted fresh warnings that it risks turning critical infrastructure sector operators into lucrative targets, even as it has triggered a surge in DDoS attacks, website defacements, and hack-and-leak operations against Israel and Western organizations. Hacktivists entities have also engaged in psychological warfare and influence operations with an aim to sow fear and confusion among the targeted populations. In recent weeks, the energy sector in the Middle East has drawn the attention of a relatively new cybercriminal group called Nasir Security. The group, instead of directly targeting energy companies, has gone after their contractors and third-parties to leak internal data, leading to "incorrect assumptions" about the origin of hacks. "The group is attacking supply chain vendors involved in engineering, safety, and construction," Resecurity said. "The supply chain attacks attributed to Nasir Security are likely carried out by cyber-mercenaries or individuals hired or sponsored by Iran or its proxies." "The cyber activity tied to this conflict is becoming increasingly decentralized and destructive," Kathryn Raines, cyber threat intelligence team lead for the National Security Solutions at Flashpoint, said in a statement. "Groups like Handala and Fatimion are targeting private-sector organizations with attacks designed to erase data, disrupt services, and introduce uncertainty for both businesses and the public. At the same time, we're seeing a greater use of legitimate administrative tools in these cyber operations, making it significantly harder for traditional security controls to detect." That's not all. MOIS-linked actors have been increasingly engaging with the cybercrime ecosystem to support its objectives and provide a cover for its malicious activity. This includes Handala's integration of Rhadamanthys stealer into its operations and MuddyWater's use of the Tsundere botnet (aka Dindoor) and Fakeset, the latter of which is a downloader used to deliver CastleLoader. "Such engagement offers a dual advantage: it enhances operational capabilities through access to mature criminal tooling and resilient infrastructure, while complicating attribution and contributing to recurring confusion around Iranian threat activity," Check Point said. "The use of such tools has created significant confusion, leading to misattribution and flawed pivoting, and clustering together activities that are not necessarily related. This demonstrates that the use of criminal software can be effective for obfuscation, and highlights the need for extreme caution when analyzing overlapping clusters."
3 shared
Apr 2, 2026