U.S. authorities indicted three Iranian nationals—Said Pourkarim Arabi, Mohammad Reza Espargham, and Mohammad Bayati—for cyber intrusions conducted between 2015 and 2019 against aerospace and satellite technology companies, alleging they stole sensitive commercial information, intellectual property, and personal data on behalf of the Islamic Revolutionary Guard Corps (IRGC). Reporting on the case linked the activity to Iranian espionage tradecraft associated with Elfin (APT33), including spear-phishing, use of the NanoCore RAT, exploitation of CVE-2018-20250 in WinRAR, and follow-on intrusion activity using malicious HTA files, mshta.exe, and PowerShell in regional targeting such as Saudi Arabia.
The enforcement action aligns with broader U.S. efforts against Iranian cyber operators, including OFAC sanctions on APT39 (Chafer), the Rana Intelligence Computing Company front, and MOIS-linked personnel for surveillance and intrusions targeting Iranian citizens, neighboring governments, and foreign organizations. Separate threat research also described an Iranian espionage campaign dubbed Operation GhostShell, which targeted aerospace and telecommunications firms across the Middle East, the United States, Russia, and Europe with the ShellClient RAT, a stealthy backdoor that disguised itself as legitimate Windows components and in newer variants used the Dropbox API for command-and-control.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On 2020-09-17, the U.S. Treasury's OFAC added APT39, also known as Chafer, and Rana Intelligence Computing Company to the SDN List under the IRAN-HR program. OFAC identified both as linked to Iran's Ministry of Intelligence and Security and also designated numerous associated individuals.
On 2020-09-17, the FBI, coordinated with DHS-CISA, issued a Private Industry Notification on IRGC-associated cyber operations targeting U.S. and foreign aerospace, satellite, and international government organizations. The notice identified the indicted Iranian nationals, described their spear-phishing and follow-on intrusion methods, and published historical indicators and tooling including Metasploit, Mimikatz, NanoCore RAT, OCRA stagers, and a Python backdoor.
In late August 2019, Elfin compromised a victim in Saudi Arabia using a malicious HTA file delivered after the victim visited a malicious website in Microsoft Edge. The intrusion used mshta.exe and follow-on PowerShell activity to retrieve additional payloads from spoofed dynamic DNS infrastructure.
In June 2019, Elfin sent phishing emails to hundreds of recipients across multiple countries in an opportunistic trawling campaign. The emails linked to dynamic DNS infrastructure controlled by the group.
In February 2019, Elfin attempted to exploit CVE-2018-20250 in WinRAR to compromise an organization in Saudi Arabia's chemical sector. Symantec cited this as part of the group's recent operations.
Cybereason assessed that the Iranian threat actor it named MalKamak has operated since at least 2018. The group was later linked to espionage targeting aerospace and telecommunications organizations.
Cybereason assessed that the previously undocumented ShellClient RAT had been under active development since at least 2018. The malware later became the primary espionage tool in Operation GhostShell.
According to a U.S. indictment, Said Pourkarim Arabi, Mohammad Reza Espargham, and Mohammad Bayati carried out cyber attacks against aerospace and satellite technology companies between 2015 and 2019. The alleged operations used fake identities and spear-phishing to steal sensitive commercial information, intellectual property, and personal data on behalf of the IRGC.
Symantec said it has tracked the Iranian espionage group Elfin, also known as APT33, since late 2015. The group was associated with spear-phishing and scanning for vulnerable websites to gain access or support command-and-control operations.
Cybereason stated that the Operation GhostShell threat remained active as of September 2021. The campaign continued to use ShellClient for espionage against targeted organizations.
In July 2021, Cybereason investigated Operation GhostShell, a cyber-espionage campaign targeting aerospace and telecommunications organizations primarily in the Middle East, with additional victims in the United States, Russia, and Europe. During the investigation, researchers identified the ShellClient RAT and attributed the campaign to a newly named Iranian actor, MalKamak.
A ShellClient malware sample analyzed by Cybereason was compiled on 2021-05-22. The sample masqueraded as legitimate Windows binaries and supported stealthy espionage functions including Dropbox-based command-and-control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourcehome.treasury.gov
Open sourcecybereason.com
Open sourcesymantec.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.