PULSE NAME
Forges Recruitment Sites, Launches Attacks on Aerospace and Semiconductor Industries in Multiple Countries
WHITE APT35 AlienVault 2024-12-04 Modified: 2024-12-04
16
IOCs
MEDIUM VOLUME
In this analysis, researchers have uncovered a malicious campaign orchestrated by APT35, a threat group believed to be affiliated with the Islamic Revolutionary Guard Corps (IRGC) of Iran. The group has been observed using forged recruitment sites and corporate sites to target the aerospace and semiconductor industries across multiple countries, including the United States, Thailand, the United Arab Emirates, and Israel. The attackers lure victims into downloading and executing malicious processes under the guise of site access or VPN access. The campaign leverages legitimate internet resources such as OneDrive, Google Cloud, and GitHub, and employs various tactics to evade detection and facilitate its operations. The detailed report provides an in-depth examination of the attack methods, infrastructure, and indicators of compromise (IOCs) associated with this campaign.
Indicators of Compromise (16)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3528837b4088a22f0043551431809b3d 2024-12-04
FileHash-MD5 f3f929ae713cb1952159ba80d5eb6214 2024-12-04
FileHash-SHA1 1123333d1db9ecbb747fc15d69ec9d984f1059fe 2024-12-04
FileHash-SHA1 1acd34fb6de5c645e03ded9875046979be7893c4 2024-12-04
FileHash-SHA256 88097e4780bfdc184b16c5a8a90793983676ad43749ffca49c9d70780e32c33a 2024-12-04
FileHash-SHA256 c1f1ce81115bed45c594aeeb92adb687bb04478cb40bb9dab538277d0c8cc13e 2024-12-04
FileHash-SHA256 cfdc7747b716be5817ce1bc76decfb3e1b27113545a01558ed97ab5fd024c53e 2024-12-04
FileHash-SHA256 db034eb09fea48cc77d19804126f64c5336dd4e33b3884dc33d5336a434cb315 2024-12-04
URL http://xboxapicenter.com/ 2024-12-04
URL https://quiz.careers2find.com 2024-12-04
domain msdnhelp.com 2024-12-04
domain visioffline.com 2024-12-04
domain xboxapicenter.com 2024-12-04
hostname cdn.careers2find.com 2024-12-04
hostname customer.orbotech.info 2024-12-04
hostname quiz.careers2find.com 2024-12-04