Reaper is an advanced persistent threat (APT) that has been active since at least 2017 and continues to target organizations in various industries, including government agencies, healthcare providers, and financial institutions. It uses a variety of techniques such as spear-phishing emails, watering hole attacks, and exploiting vulnerabilities in software or systems to gain access to networks and steal sensitive information. Reaper is known for its ability to persist within an organization\'s network over time, making it difficult to detect and remove. It has been linked to the Iranian government-sponsored APT group called \"OilRig.\"
Techniques, tactics and practices:
Reaper uses a variety of techniques such as spear-phishing emails, watering hole attacks, and exploiting vulnerabilities in software or systems to gain access to networks. It also employs stealthy tactics like hiding its malware within legitimate files, using encryption to protect itself from detection, and using multiple layers of obfuscation techniques to evade security tools. Reaper is known for its ability to persist within an organization\'s network over time, making it difficult to detect and remove. It has been linked to the Iranian government-sponsored APT group called \"OilRig.\"
