Iranian threat actor UNC2428 has been observed deploying the MURKYTOUR backdoor in a sophisticated job-themed social engineering campaign targeting Israelis in October 2024, according to Mandiant’s 2025 M-Trends report.
The attackers posed as recruiters from Israeli defense contractor Rafael, directing interested individuals to an impersonation website where victims were prompted to download “RafaelConnect.exe.” This installer, dubbed LONEFLEET, presented a legitimate-looking GUI requesting personal information and resumes. Once submitted, the MURKYTOUR backdoor was secretly launched via the LEAFPILE loader, giving attackers persistent access to compromised systems.
“The addition of a GUI that mimics the form and function of the lure can reduce suspicions from targeted individuals,” Mandiant explained.
This campaign aligns with activities attributed to Black Shadow, a group believed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS), which targets various Israeli sectors including academia, finance, government, and technology.
## Other Iranian Threat Actors Targeting Israel
Several other Iranian threat groups have intensified operations against Israel in 2024:
– **Cyber Toufan**: Deployed the POKYBLIGHT wiper malware
– **UNC3313**: Conducted surveillance operations using spear-phishing campaigns distributing JELLYBEAN dropper and CANDYBOX backdoor
– **MuddyWater affiliates**: Utilized up to nine legitimate remote monitoring tools to evade detection
– **APT42 (Charming Kitten)**: Created elaborate social engineering campaigns with fake login pages impersonating Google, Microsoft, and Yahoo!
– **APT34 (OilRig)**: Employed DODGYLAFFA and SPAREPRIZE backdoors against Iraqi government targets
Mandiant identified over 20 proprietary malware families used by Iranian actors in Middle Eastern campaigns during 2024. These threat actors are increasingly incorporating cloud infrastructure into their operations to blend in with legitimate enterprise services, using techniques like typosquatting and domain reuse to reduce scrutiny.
As Iranian cyber operations continue to align with regime interests, their methodologies will likely continue evolving to adapt to the changing security landscape.
