07 octombrie 2021

Iran-linked MalKamak Hackers Targeting Aerospace, Telcos With ShellClient RAT

securityweek.com

Operation GhostShell Believed to be Linked to Iranian Threat ActorResearchers have discovered a previously unknown advanced threat actor, probably of Iranian origin, using a previously undocumented RAT targeting largely aerospace and telecommunications organizations. They have named the group MalKamak , and the campaign Operation GhostShell .Cybereason first detected the threat actor engaged in cyber espionage with the unknown remote access trojan – which it called ShellClient – in July 2021. [...]