Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Iran MOIS phishes 50+ embassies, ministries, international organizations

(Le Vu / Unsplash)

By Nate Nelson

Iranian state hackers used a treasure trove of compromised email accounts to phish dozens of worldwide diplomatic missions.

Researchers from Dream Security and Clear Sky Cyber Security have both since tied this activity to the advanced persistent threat (APT) known colloquially as “Homeland Justice,” associated with Iran’s Ministry of Intelligence (MOIS). The key to Homeland Justice’s strategy was 104 unique, variously official, compromised addresses, which it used to send emails under the guise of official government business. Attached to those emails, of course, were files carrying infostealing malware.

The first email in this campaign was sent Aug. 19. It was generated using a legitimate address belonging to the Oman Ministry of Foreign Affairs in Paris, and directed right back at the organization from whence it came.

Read more at Dark Reading

Click to listen highlighted text!