APT34 Targeting US Company Through Spear Phishing eMail
(January 31, 2020)
A hacker group with ties to Iran has been sending spear phishing emails to customers and employees of a company that works with US federal, state, and local governments. The phony messages sent to Westat employees contain malicious Excel spreadsheet attachments. The spreadsheets appear to be black; if recipients enable macros, the content - a phony job satisfaction survey - appears and malware that installs the TONEDEAF backdoor is downloaded in the background.
https://www.sans.org/newsletters/newsbites/xxii/10
Iranian Hackers Target U.S. Gov. Vendor With Malware:
https://threatpost.com/iran-hackers-us-gov-malware/152452/