The Register Home Page

back to article Suspected Iran-backed attackers targeting European aerospace sector with novel malware

Suspected Iranian government-backed online attackers have expanded their European cyber ops with fake job portals and new malware targeting organizations in the defense, manufacturing, telecommunications, and aviation sectors. In a Monday report, Check Point Research says it's been tracking "waves" of this activity since early …

  1. VoiceOfTruth Silver badge

    Checkpoint

    An American company which operates internationally, providing backdoors for the American regime. Yeah.

    1. NoneSuch Silver badge
      Joke

      Re: Checkpoint

      It's "novel malware" so it only affects ebooks. Right? Right!?

  2. JimmyPage Silver badge
    Linux

    First, the victim runs a legitimate Windows executable from the archive,

    I have an immediate suggestion to stop this in it's tracks. One that I suspect a lot of real IT professionals (not script kiddies) will already have in place.

    It does beg the question about the level of mark the phishing is trying to reel in.

    1. cyberdemon Silver badge
      Facepalm

      Re: First, the victim runs a legitimate Windows executable from the archive,

      Windows Defender, no less...

      One might've thought that a security app like that would have secure code-signing for DLLs ...

      Less Windows Defender, more Windows Defenestrator

      1. TimMaher Silver badge
        Coat

        Re: Windows Defender

        Could have been worse.

        Could have been Land Rover Defender.

        Except JLR haven’t got any.

  3. Doctor Syntax Silver badge

    " Nimbus Manticore – also known as UNC1549 (by Google), Smoke Sandstorm (Microsoft), and Imperial Kitten."

    Make up your minds - one crew, one name would make your lives a bit and everyone else's a lot easier.

    1. Tom66

      I feel like these names are far too "cool" for what are essentially criminals. How about "Hacker group ABC123"?

      1. TimMaher Silver badge
        Trollface

        I was thinking that.

        Came up with “Tosser 123”.

  4. Anonymous Coward
    Anonymous Coward

    Now About NSO and Paragon Malware........

    .....attacking IOS and Android.......

    .....so Twentieth Century.......describing attacks on Windows.............

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like