Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access

April 18, 2023Rabbi LakshmananCyber ​​Threat/Malware

SimpleHelp remote support

An Iranian threat actor known as MuddyWater continues a long-standing tradition of relying on legitimate remote administration tools to loot targeted systems.

The nation-state group previously employed ScreenConnect, RemoteUtilities, and Syncro, but new analysis by Group-IB reveals the attackers used SimpleHelp remote support software in June 2022 .

MuddyWater has been active since at least 2017 and is rated as a subordinate element within Iran’s Ministry of Information and Security (MOIS). Primary targets include Turkey, Pakistan, UAE, Iraq, Israel, Saudi Arabia, Jordan, United States, Azerbaijan, and Afghanistan.

Group-IB Senior Threat Analyst Nikita Rostovtsev said:

“SimpleHelp has not been compromised and is being used as intended. The attackers found a way to download the tool from the official website and use it in their attacks.”

SimpleHelp remote support

The exact distribution method used to drop the SimpleHelp sample is currently unknown, but the group has been known to send spear-phishing messages containing malicious links from mailboxes of companies that have already been compromised. increase.

Group-IB’s findings were corroborated by Slovak cybersecurity firm ESET earlier this year, revealing details of MuddyWater attacks in Egypt and Saudi Arabia. The attack required SimpleHelp to deploy the Ligolo reverse tunneling tool and a credential harvester called MKL64.

upcoming webinars

Master the Art of Dark Web Intelligence Gathering

Learn the art of extracting threat intelligence from the dark web – join us for this expert-led webinar!

Save my seat!

The Singapore-based company also said it had identified a previously unknown infrastructure operated by the group, as well as a PowerShell script capable of receiving commands from remote servers and sending results back to them. .

The disclosure comes just weeks after Microsoft detailed a group’s modus operandi to carry out devastating attacks in a hybrid environment under the guise of a ransomware operation.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *