APT 4HCrew is a suspected nation-state hacking group believed to be associated with Iranian intelligence services. First identified in 2015, this advanced persistent threat (APT) actor has primarily targeted government, defense, and academic organizations across the Middle East and North Africa.
Key characteristics:
- Targets: Government agencies, military/defense contractors, universities, and think tanks in countries like Saudi Arabia, UAE, Turkey, and Israel.
- Tactics: Spear-phishing emails, watering hole attacks, and exploitation of known vulnerabilities.
- Tools: Custom malware including TUNNA backdoor and MUDDYC3 remote access trojan.
- Objectives: Cyber espionage, data theft, and intelligence gathering on regional rivals.
Notable campaigns:
- 2017 attack on the Saudi aviation sector using DUSTYSKY malware
- 2019 operations against Bahraini government ministries
- 2020 campaign targeting Israeli defense companies
Attribution to Iran remains circumstantial, based on targeting patterns, Farsi language artifacts in malware, and infrastructure overlap with other suspected Iranian APTs. However, 4HCrew's activities align with Iran's geopolitical interests in the region.
