TA402 Uses Complex IronWind Infection Chains to Target Middle East-Based Government Entities

In mid-2023, Proofpoint researchers first identified TA402 (Molerats, Gaza Cybergang, Frankenstein, WIRTE) activity using a labyrinthine infection chain to target Middle Eastern governments with a new initial access downloader Proofpoint has dubbed IronWind. From July through October 2023, TA402 utilized Read More …

Suspected espionage in Palestine highlights spread of hacking skills

A wave of recent espionage activity from suspected Palestinian hackers is the latest evidence that wealthy spy agencies no longer are the sole operators of malware that covertly vacuums up victims’ data. A shadowy group has targeted governments in the Read More …

Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations

Between October 2019 through the beginning of December 2019, Unit 42 observed multiple instances of phishing attacks likely related to a threat group known as Molerats (AKA Gaza Hackers Team and Gaza Cybergang) targeting eight organizations in six different countries Read More …

New Cyber Espionage Campaigns Targeting Palestinians: The Spark and Pierogi Campaigns

Over the last several months, the Cybereason Nocturnus team has been tracking recent espionage campaigns targeting the Middle East. These campaigns are specifically directed at entities and individuals in the Palestinian territories. This investigation shows multiple similarities to previous attacks Read More …