Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts post, oktober 17, 2024juli 3, 2025 A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm) is a group that has been previously tied to the Iranian Ministry of Intelligence and Security (MOIS). It’s known to spy on high-value targets in major industries across the Middle East: oil and gas; finance; chemicals; telecommunications; other forms of critical infrastructure; and governments. Its attacks have demonstrated a sophistication befitting its targets, with suites of custom malware and an ability to evade detection for long periods of time. Iran’s APT34 Abuses MS Exchange (darkreading.com): Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts malware vulnerability 2024APT34Iran