New Targeted Attack in the Middle East by APT34, a Suspected Iranian
Threat Group, Using CVE-2017-11882 Exploit[html]
Less than a week after Microsoft issued a patch for href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11882">CVE-2017-11882
on Nov. 14, 2017, FireEye observed an attacker using an exploit for
the Microsoft Office vulnerability to target a government organization
in the Middle East. We assess this activity was carried out by a
suspected Iranian cyber espionage threat group, whom we refer to as
APT34, using a custom PowerShell backdoor to achieve its objectives.
We believe APT34 is involved in a long-term cyber espionage
operation largely focused on reconnaissance efforts to benefit Iranian
nation-state interests and has been operational since at least 2014.
This threat group has conducted broad targeting across a variety of
industries, including financial, government, energy, chemical, and
telecommunications, and has largely focused its operations within the
Middle East. We assess that APT34 works on behalf of the Iranian
government based on infrastructure details that contain references to
Iran, use of Iranian infrastructure, and targeting that aligns with
nation-state interests.
APT34 uses a mix of public and non-public tools, often conducting
spear phishing operations using compromised accounts, sometimes
coupled with social engineering tactics. In May 2016, we