Friday Dec 5, 2025
NEWSLETTER
www.israelhayom.com
  • Home
  • News
    • Israel
    • Israel at War
    • Middle East
    • United States
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
  • In Memoriam
www.israelhayom.com
  • Home
  • News
    • Israel
    • Israel at War
    • Middle East
    • United States
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
  • In Memoriam
www.israelhayom.com
Home Science & Technology Cyber & Internet

Iranian cyber espionage exposed by US-Israeli security experts at Cybereason

Researchers at Cybereason identify two campaigns by Iranian state actors that use malware to target organizations all over the world.

by  Assaf Golan and ILH Staff
Published on  02-01-2022 10:50
Last modified: 02-01-2022 11:00
Iranian cyber espionage exposed by US-Israeli security experts at CybereasonMicha Lubton

The Cybereason offices | Courtesy: Micha Lubton

Share on FacebookShare on Twitter

Iran is using malware variants in two separate state-sponsored cyber espionage operations around the globe, the XDR (extended detection and response) cybersecurity research company Cybereason announced Tuesday.

Follow Israel Hayom on Facebook, Twitter, and Instagram

According to Cybereason, the Iranian malware cyber espionage is targeting a wide range of organizations in different parts of the world. Researchers identified a previously undocumented remote access trojan (RAT) named "StrifeWater" that the company attributes to Iranian threat actor Moses Staff. This APT (advanced persistent threat) has been noted targeting organizations in the US, Israel, India, Germany, Italy, United Arab Emirates, Chile and Turkey.

After infiltrating an organization and exfiltrating sensitive data, the attackers deploy destructive ransomware to cause operational disruptions and make forensic investigation more difficult.

Cybereason also discovered a new set of tools developed by the Phosphorus group (also known as Charming Kitten, APT35) that includes a novel PowerShell-based backdoor dubbed "PowerLess," as well as an IP address used in the attacks that was previously identified as part of the command and control (C2) for the recently documented Memento ransomware.

Cybereason CEO Lior Div Cybereason

Phosphorus is known for attacking medical and academic research organizations, human rights activists, the media, and exploiting known Microsoft Exchange Server vulnerabilities and for attempting to interfere with US elections.

The company observed similar abuse of open-source tools in both Iranian cyberattack operations.

Cybereason co-founder and CEO Lior Div explained that the recently discovered Iranian cyber espionage campaigns "highlight the blurred line between nation-state and cybercrime threat actors, where ransomware gangs are more often employing APT-like tactics to infiltrate as much of a targeted network as possible without being detected, and APTs leveraging cybercrime tools like ransomware to distract, destroy and ultimately cover their tracks."

According to Div, "there is no longer a significant distinction between nation-state adversaries and sophisticated cybercriminal operations. That's why it is crucial for us as [cyber] defenders to collectively improve our detection and prevention capabilities if we are going to keep pace with these evolving threats."

Subscribe to Israel Hayom's daily newsletter and never miss our top stories!

 

Tags: cybersecurityIranmalware

Related Posts

Israeli tech firm finds AI vulnerability – Gemini susceptibleReuters/Dado Ruvic/Illustration

Israeli tech firm finds AI vulnerability – Gemini susceptible

by ILH Staff and Miri Weissman

They exploit how AI browsers interpret instructions after the hashtag symbol. This effectively creates a new subcategory of cyber threats...

Netanyahu shares article from anti-Israel magazine linking Epstein to 2019 electionsEPA/Abir Sultan

Netanyahu shares article from anti-Israel magazine linking Epstein to 2019 elections

by Bini Ashkenazi

The piece also revived conspiracy claims that Epstein acted as a Mossad agent, allegations Israeli officials have firmly denied.

X's location feature exposes fake Gaza accountsAP /Adel Hana

X's location feature exposes fake Gaza accounts

by Avital Fried

"Huge accounts in the West whose main content is Israel, spreading blood libels and more are actually in Pakistan, Bangladesh,...

Menu

Analysis 

Archaeology

Blogpost

Business & Finance

Culture

Exclusive

Explainer

Environment

 

Features

Health

In Brief

Jewish World

Judea and Samaria

Lifestyle

Cyber & Internet

Sports

 

Diplomacy 

Iran & The Gulf

Gaza Strip

Politics

Shopping

Terms of use

Privacy Policy

Submissions

Contact Us

About Us

The first issue of Israel Hayom appeared on July 30, 2007. Israel Hayom was founded on the belief that the Israeli public deserves better, more balanced and more accurate journalism. Journalism that speaks, not shouts. Journalism of a different kind. And free of charge.

All rights reserved to Israel Hayom

Hosted by sPD.co.il

  • Home
  • News
    • Israel at War
    • Israel
    • United States
    • Middle East
    • Sports
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
    • Environment & Wildlife
    • Health & Wellness
  • In Memoriam
  • Subscribe to Newsletter
  • Submit your opinion
  • Terms and conditions

All rights reserved to Israel Hayom

Hosted by sPD.co.il

Newsletter

[contact-form-7 id=”508379″ html_id=”isrh_form_Newsletter_en” title=”newsletter_subscribe”]

  • Home
  • News
    • Israel at War
    • Israel
    • United States
    • Middle East
    • Sports
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
    • Environment & Wildlife
    • Health & Wellness
  • In Memoriam
  • Subscribe to Newsletter
  • Submit your opinion
  • Terms and conditions

All rights reserved to Israel Hayom

Hosted by sPD.co.il