Iranian Hackers Exploit VPN Vulnerabilities to Infiltrate Middle East Critical Infrastructure for 2 Years


# Iranian State-Sponsored Group Targets Critical Infrastructure in Two-Year Cyber Campaign

A sophisticated cyber intrusion targeting critical national infrastructure (CNI) in the Middle East has been attributed to an Iranian state-sponsored threat group known as Lemon Sandstorm. According to FortiGuard Incident Response (FGIR), the attack persisted from May 2023 to February 2025, involving extensive espionage operations and network prepositioning tactics designed to maintain persistent access.

Lemon Sandstorm, also tracked as Parisite, Pioneer Kitten, and UNC757, has been active since at least 2017, primarily targeting aerospace, oil and gas, water, and electric sectors across the United States, Middle East, Europe, and Australia. The group is known for exploiting VPN vulnerabilities in products from Fortinet, Pulse Secure, and Palo Alto Networks.

## Attack Timeline and Tactics

The intrusion unfolded in four distinct phases:

**Phase 1 (May 2023 – April 2024)**: Attackers established their foothold using stolen VPN credentials, deployed web shells on public-facing servers, and installed three backdoors (Havoc, HanifNet, and HXLibrary) for persistent access.

**Phase 2 (April – November 2024)**: The group consolidated their position by planting additional web shells and deploying NeoExpressRAT backdoor. They used tools like plink and Ngrok to penetrate deeper into the network, exfiltrated emails, and moved laterally to virtualization infrastructure.

**Phase 3 (November – December 2024)**: In response to the victim’s containment efforts, attackers deployed more web shells and two additional backdoors: MeshCentral Agent and SystemBC.

**Phase 4 (December 2024 onward)**: After being removed from the network, the attackers attempted to regain access by exploiting Biotime vulnerabilities (CVE-2023-38950, CVE-2023-38951, and CVE-2023-38952) and launching spear-phishing campaigns targeting 11 employees to harvest Microsoft 365 credentials.

## Malware Arsenal

The attackers employed a mix of custom malware and open-source tools:

– **HanifNet**: A .NET executable retrieving commands from C2 servers

– **HXLibrary**: A malicious IIS module using Google Docs to fetch C2 server information

– **CredInterceptor**: A tool for harvesting credentials from Windows LSASS

– **RemoteInjector**: A loader for executing payloads like Havoc

– **NeoExpressRAT**: A backdoor likely using Discord for communications

– **SystemBC**: A commodity malware often preceding ransomware deployment

The attribution to Lemon Sandstorm is based on shared C2 infrastructure, including domains like apps.gist.githubapp[.]net and gupdate[.]net, previously linked to the group’s operations.

While the attackers extensively targeted OT-adjacent systems, there is no evidence they penetrated the restricted OT network. Forensic analysis suggests the threat actor may have initially accessed the network as early as May 2021, with most activities appearing to be manual operations conducted by multiple individuals following consistent work schedules.

Share This Article