{"id":428,"date":"2024-10-17T10:13:58","date_gmt":"2024-10-17T10:13:58","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=428"},"modified":"2025-07-03T07:28:49","modified_gmt":"2025-07-03T05:28:49","slug":"irans-apt34-abuses-ms-exchange-to-spy-on-gulf-govts","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2024\/10\/17\/irans-apt34-abuses-ms-exchange-to-spy-on-gulf-govts\/","title":{"rendered":"Iran&#8217;s APT34 Abuses MS Exchange to Spy on Gulf Gov&#8217;ts"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm) is a group that has been previously tied to the Iranian Ministry of Intelligence and Security (MOIS). It&#8217;s known to spy on\u00a0<a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/iran-oilrig-cyberattackers-target-israel-critical-infrastructure\">high-value targets in major industries<\/a>\u00a0across the Middle East: oil and gas; finance; chemicals; telecommunications; other forms of critical infrastructure; and governments. Its attacks have demonstrated a sophistication befitting its targets, with suites of custom malware and an ability to\u00a0<a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/iran-linked-muddywater-spies-middle-east-govt-eight-months\">evade detection for long periods of time<\/a>.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2024\/10\/17\/irans-apt34-abuses-ms-exchange-to-spy-on-gulf-govts\/\" target=\"_self\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/iran-apt34-ms-exchange-spy-gulf-govts\">Iran&#8217;s APT34 Abuses MS Exchange (darkreading.com)<\/a><span class=\"screen-reader-text\">: Iran&#8217;s APT34 Abuses MS Exchange to Spy on Gulf Gov&#8217;ts<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm)&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,17],"tags":[31,61,15],"class_list":["post-428","post","type-post","status-publish","format-standard","hentry","category-malware","category-vulnerability","tag-31","tag-apt34","tag-iran"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=428"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/428\/revisions"}],"predecessor-version":[{"id":429,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/428\/revisions\/429"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=428"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}