Wednesday, March 12, 2025
No menu items!
HomeUncategorizedSuspected Iranian Hackers Use Compromised Indian Firm’s Email to Target UAE Aviation...

Suspected Iranian Hackers Use Compromised Indian Firm’s Email to Target UAE Aviation Sector

How Iranian-Aligned Hackers Exploited Trusted Relationships to Target Critical UAE Infrastructure

A new, highly-targeted phishing campaign aimed at the United Arab Emirates (UAE) aviation sector has been linked to Iranian-aligned hackers. The attackers used a compromised email account from Indian electronics company INDIC Electronics to send phishing emails containing a sophisticated Golang backdoor, Sosano.

The emails, which were tailored to each target, contained malicious ZIP files that included a mix of polyglot files, such as a Windows shortcut disguised as an Excel document and two PDF files. One of these PDFs triggered the execution of a custom backdoor upon parsing.

The malicious backdoor, written in Golang, allows attackers to control compromised systems, execute commands, enumerate directories, and download further payloads. This attack specifically targeted fewer than five organizations, including those in aviation and satellite communications, sectors critical to the UAE’s national security.

The campaign, tracked by Proofpoint under the moniker “UNK_CraftyCamel,” suggests a sophisticated level of obfuscation and the use of a trusted third-party compromise to evade detection. The analysis points to Iranian state-sponsored actors, possibly linked to the Islamic Revolutionary Guard Corps (IRGC), highlighting the geopolitical motivations behind the attack.

Fintter Security
Fintter Securityhttps://fintter.com
I’m a cybersecurity expert focused on protecting digital infrastructures for fintech and enterprise businesses. I specialize in Open Source Intelligence (OSINT) and use social media insights to help drive business development while defending against cyber threats. I offer full security services, including firewall setup, endpoint protection, intrusion detection, and secure network configurations, ensuring your systems are secure, well-configured, and maintained. I’m available for consultancy and security services. Contact me at info@fintter.com or via WhatsApp at +2349114199908 to discuss how I can strengthen your organization’s cybersecurity and business growth.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

Recent Comments