APT Charming Kitten Pounces on Medical Researchers
#1
Information 
Quote:Security researchers have linked a late-2020 phishing campaign aimed at stealing credentials from 25 senior professionals at medical research organizations in the United States and Israel to an advanced persistent threat group with links to Iran called Charming Kitten.
 
The campaign—dubbed BadBlood because of its medical focus and the history of tensions between Iran and Israel–aimed to steal credentials of professionals specializing in genetic, neurology and oncology research, according to new research posted online Wednesday from Proofpoint’s Joshua Miller and the Proofpoint Research Team.
 
This type of targeting represents a departure for Charming Kitten, (also known as Phosphorus, Ajax or TA453), which—due to its believed alignment with Iran’s Islamic Revolutionary Guard Corps (IRGC)–in the past has primarily put dissidents, academics, diplomats and journalists in its crosshairs, researchers said in the report.
 
“While this campaign may represent a shift in TA453 targeting overall, it is also possible it may be the result of a specific short-term intelligence collection requirement,” Miller and the team wrote in a report. “BadBlood is aligned with an escalating trend of medical research being increasingly targeted by threat actors.”
 
Indeed, the medical professionals targeted in the latest campaign “appear to be extremely senior personnel” at their respective organizations, researchers noted. Though Proofpoint hasn’t conclusively determined Charming Kitten’s motives for the attacks, it does seem to be a one-off attempt to gather intelligence that potentially can be used in further phishing campaigns, they said.

Read more: APT Charming Kitten Pounces on Medical Researchers | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
APT Charming Kitten Pounces on Medical Researchers - by silversurfer - 01 April 21, 17:13

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Google to End Manifest V2 Support in Chr...
Google will remove...harlan4096 — 11:55
NanaZip 6.5 (6.5.1750.0)
NanaZip 6.5 (6.5.1...harlan4096 — 10:49
AnyDesk 9.7.1 for macOS
Version 9.7.1 for ...harlan4096 — 10:48
Internet Download Manager 6.32 Build 9
Internet Download ...Kool — 06:51
K-Lite Codec Pack 19.7.5 / 19.7.7 Update
Changes in 19.7.7 ...harlan4096 — 06:10

[-]
Birthdays
Today's Birthdays
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>