GBHackers News reports that Iranian dissidents and activists have been continuously targeted by the Ferocious Kitten advanced persistent threat operation since its emergence in 2015.Ferocious Kitten commenced its spear-phishing attacks with the delivery of illicit Microsoft Office files purporting to be political documents, which had macros or MSHTML exploits that launched the MarkiRAT malware, according to Picus Security researchers.Aside from featuring an advanced keystroke and clipboard logger, which is only enabled upon the disablement of password managers, MarkiRAT also leverages HTTP and HTTPS requests to communicate with its command-and-control server, as well as uses GET and POST techniques to facilitate extensive data exfiltration.Further analysis showed that Ferocious Kitten not only conducts start menu persistence and app directory takeovers, but also exploits the RTLO unicode trick and the Windows BITS tool to ensure stealthy operations.Combating Ferocious Kitten's threat requires increased vigilance and improved user training, as well as persistent security control validation, researchers said.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




