Anonymous ID: d90eca Feb. 7, 2020, 6:40 p.m. No.8068551   🗄️.is 🔗kun

APT34 Targeting US Company Through Spear Phishing eMail

 

(January 31, 2020)

 

A hacker group with ties to Iran has been sending spear phishing emails to customers and employees of a company that works with US federal, state, and local governments. The phony messages sent to Westat employees contain malicious Excel spreadsheet attachments. The spreadsheets appear to be black; if recipients enable macros, the content - a phony job satisfaction survey - appears and malware that installs the TONEDEAF backdoor is downloaded in the background.

 

https://www.sans.org/newsletters/newsbites/xxii/10

 

Iranian Hackers Target U.S. Gov. Vendor With Malware:

https://threatpost.com/iran-hackers-us-gov-malware/152452/