PULSE NAME
Iranian Dream Job campaign
WHITE TA455 AlienVault 2024-11-12 Modified: 2024-12-12
12
IOCs
MEDIUM VOLUME
An Iranian campaign targeting the aerospace industry has been uncovered, distributing SnailResin malware through a 'dream job' scheme. Attributed to TA455, a subgroup of Charming Kitten, the campaign uses social engineering tactics on LinkedIn, impersonating recruiters to lure victims. The attack employs multi-stage infection chains, DLL side-loading, and leverages legitimate services like Cloudflare and GitHub to evade detection. The campaign has been active since September 2023, constantly evolving its infrastructure and malware. Similarities with North Korean Lazarus Group tactics suggest either impersonation or shared attack methods. The campaign primarily targets aerospace, aviation, and defense industries in the Middle East, especially Israel and UAE.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SnailResin SlugResin
Indicators of Compromise (12)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 bb4c8f42cc624c628e4b98bd43f29fa6 2024-11-12
FileHash-SHA1 1acd34fb6de5c645e03ded9875046979be7893c4 2024-11-12
FileHash-SHA1 21b0327e7ccb36d9ba00359e078acaa9a2320c83 2024-11-12
FileHash-SHA1 2a29ba7302024ec1255811abec2a532136d12fef 2024-11-12
FileHash-SHA1 2e7fc6d63ce16075a3fe3584e03be24a9bc220e1 2024-11-12
FileHash-SHA1 3a0b3426f4a2f85e0c82b2804aab7f5d5bb63fb7 2024-11-12
FileHash-SHA1 aa5fcea406edd406bd6e0a23e83beebe2b3582d1 2024-11-12
FileHash-SHA1 c52beb64f7450fce923d15efaa1e5be4c0e43d2b 2024-11-12
FileHash-SHA256 bf308e5c91bcd04473126de716e3e668cac6cb1ac9c301132d61845a6d4cb362 2024-11-12
domain careers2find.com 2024-11-12
domain xboxapicenter.com 2024-11-12
hostname raw.ghubusercontent.com 2024-11-12