Iranian Hackers Utilize SimpleHelp Software for Long-Term Access

1 min read
Source: The Hacker News
Iranian Hackers Utilize SimpleHelp Software for Long-Term Access
Photo: The Hacker News
TL;DR Summary

Iranian threat actor MuddyWater has been using the legitimate remote support software SimpleHelp to ensure persistence on victim devices. The group, believed to be a subordinate element within Iran's Ministry of Intelligence and Security, has previously used ScreenConnect, RemoteUtilities, and Syncro. SimpleHelp is not compromised and is used as intended, with the threat actors downloading the tool from the official website. The exact distribution method used to drop the SimpleHelp samples is currently unclear, although the group is known to send spear-phishing messages bearing malicious links from already compromised corporate mailboxes.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

1 min

vs 2 min read

Condensed

72%

32991 words

Want the full story? Read the original article

Read on The Hacker News