The Iran-linked Chafer threat group broadened its surveillance-focused intrusion campaign by compromising nine additional organizations across the Middle East and beyond, including targets in telecommunications, airlines, aircraft services, IT services, payroll, engineering, and document management. Symantec reported that the group breached a major regional telecom services provider and also attempted to penetrate a large international travel reservations company, indicating a wider operational scope and growing ambition beyond its earlier victim set.
Chafer used spear-phishing Excel documents to launch infections that dropped VBS and PowerShell payloads, then deployed information-stealing and screen-capture malware before moving laterally inside victim networks. The operators also expanded their toolkit with utilities and infrastructure including Remcom, NSSM, UltraVNC, NBTScan, GNU HTTPTunnel, EternalBlue-enabled SMB tooling, and the command-and-control domain win7-updates[.]com; researchers also noted overlaps with Crambus/Oilrig in infrastructure and infection chains, though they said the evidence was insufficient to conclude the groups were the same.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
In its 2017 campaigns, Chafer adopted tools including Remcom, NSSM, EternalBlue-enabled SMB tooling, UltraVNC, NBTScan, and GNU HTTPTunnel to move laterally, persist, and remotely access victim systems.
In 2017, Chafer added a new infection method using malicious Excel spreadsheets that downloaded a VBS file to execute a PowerShell script before later deploying a dropper and surveillance tools.
Chafer attempted to compromise a large international travel reservations firm, but Symantec found no indication that the effort succeeded.
Chafer successfully infiltrated an African airline that was a customer of a large international travel reservations firm.
During its 2017 activity, Chafer compromised a major Middle Eastern telecoms services provider, apparently to facilitate surveillance of telecom end-user customers.
Throughout 2017, Chafer attacked nine new organizations across telecoms, airlines, aircraft services, IT services, payroll, engineering, and document management in the Middle East and beyond.
Symantec reported that it first exposed Chafer’s activities in December 2015.
Symantec said the Iran-based Chafer group has been active since at least July 2014.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
symantec-blogs.broadcom.com
Open sourcesymantec.com
Open sourcesymantec.com
Open sourcesymantec.com
Open sourcesymantec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.