National Cyber Warfare Foundation (NCWF)

4HCrew


1 user ratings
2024-07-26 19:53:21
blscott

 - archive -- 

APT 4HCrew is a suspected nation-state hacking group believed to be associated with Iranian intelligence services. First identified in 2015, this advanced persistent threat (APT) actor has primarily targeted government, defense, and academic organizations across the Middle East and North Africa.


Key characteristics:



  1. Targets: Government agencies, military/defense contractors, universities, and think tanks in countries like Saudi Arabia, UAE, Turkey, and Israel.

  2. Tactics: Spear-phishing emails, watering hole attacks, and exploitation of known vulnerabilities.

  3. Tools: Custom malware including TUNNA backdoor and MUDDYC3 remote access trojan.

  4. Objectives: Cyber espionage, data theft, and intelligence gathering on regional rivals.


Notable campaigns:



  • 2017 attack on the Saudi aviation sector using DUSTYSKY malware

  • 2019 operations against Bahraini government ministries

  • 2020 campaign targeting Israeli defense companies


Attribution to Iran remains circumstantial, based on targeting patterns, Farsi language artifacts in malware, and infrastructure overlap with other suspected Iranian APTs. However, 4HCrew's activities align with Iran's geopolitical interests in the region.



Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
Nation-state APT
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.