Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw...
ClearSky Team has identified a targeted Russian cyber campaign against Ukraine utilizing twonovel malware strains, BadPaw and MeowMeow. The attack chain initiates with a phishing email containing a...
View ArticleHouthi Influence Campaign
In early April, ClearSky’s team discovered a persistent Yemeni/Houthi influence campaignoperating in Israel and the Gulf states. We first exposed the campaign in 2019. It continuesto operate in a...
View ArticleCVE-2024-43451: A New Zero-Day Vulnerability Exploited in the wild
A new zero-day vulnerability, CVE-2024-43451, was discovered by ClearSky Cyber Security in June 2024. This vulnerability affects Windows systems and is being actively exploited in attacks against...
View ArticleIranian “Dream Job” Campaign 11.24
ClearSky Cyber Security research identified a campaign named “Iranian Dream Job campaign”, in which the Iranian threat actor TA455 targeted the aerospace industry by offering fake jobs. The campaign...
View ArticleDoppelgänger NG | Russian Cyberwarfare campaign
ClearSky Cyber Security and SentinelLabs have discovered a new wave of Russian information warfare campaign named Doppelgänger NG. “Doppelgänger” (meaning spirit double, an exact but usually invisible...
View Article“Homeland Justice” targets Albanian organizations with “No-justice” wiper
This blog post will elaborate on “Homeland justice” group’s background and provide an in-depth analysis of the tools used in the current attack, including reverse engineering of the NACL executable –...
View ArticleFata Morgana: Watering hole attack on shipping and logistics websites
ClearSky Cyber Security has detected a watering hole attack on at least eight Israeli websites. The attack is highly likely to be orchestrated by a nation-state actor from Iran, with a low confidence...
View ArticleLyceum suicide drone
ClearSky discovered a new malware associated with the Iranian SiameseKitten (Lyceum) group withmedium-high confidence.The file is downloaded from a domain registered on June 6th, and it communicates...
View ArticleEvilNominatus Ransomware
As part of our monitoring of malicious files in current use, we detected a malicious BAT file that was uploaded to VirusTotal from Iran. This file executes a ransomware that we associated with the...
View ArticleNew Iranian Espionage Campaign By “Siamesekitten” – Lyceum
At the beginning of May 2021, we detected the first attack by Siamesekitten on an IT company in Israel. Siamesekitten (also named Lyceum/Hexane) is an Iranian APT group active in the Middle east and...
View ArticleAttributing CryptoCore Attacks Against Crypto Exchanges to LAZARUS (North Korea)
CryptoCore is an attack campaign against crypto-exchange companies that has been ongoing for three years and was discovered by ClearSky researchers. This cybercrime campaign is focused mainly on the...
View ArticleCONTI Ransomware – Negotiation and Bitcoin Tracking
Originated by the ‘Wizard Spider’ Russian hacking group, CONTI ransomware is an evolution of one of the group’s most successful ransomware – Ryuk. CONTI is a more accessible version of Ryuk, built for...
View Article‘Lebanese Cedar’ APT
In early 2020, suspicious network activities and hacking tools were found in a range of companies. Comprehensive forensic research of the infected systems revealed a strong connection to a threat...
View ArticleOperation ‘Kremlin’
Introduction ClearSky researchers identified a malicious “.docx” file that was uploaded to VirusTotal from Russia in mid-December. The file contains an obfuscated URL to a remote template which...
View ArticlePay2Kitten – Fox Kitten 2
During the past four months a wave of cyber-attacks has been targeting Israeli companies. The attacks are conducted by different means and target a range of sectors. We estimate with medium to high...
View ArticleOperation Quicksand
During September 2020, we identified a new campaign targeting many prominent Israeli organizations. The campaign was attributed to the Iranian threat actor ‘MuddyWater’ (also known as TEMP.Zagros,...
View ArticleThe Kittens Are Back in Town 3
During 2017-2019, Clearsky had published several reports about the Iranian APT group “Charming Kitten”. One of the group’s most common attack vectors is impersonating journalists, particularly those...
View ArticleOperation ‘Dream Job’ Widespread North Korean Espionage Campaign
During June-August of 2020, ClearSky’s analysis team had investigated an offensive campaign attributed with high probability to North Korea, which we call “Dream Job”. This campaign has been active...
View ArticleCryptoCore Group
A Threat Actor Targeting Cryptocurrency Exchanges In this research, we present a hidden and persistent group, that has been targeting crypto-exchanges, mainly in the US and Japan since as early as...
View ArticleClearSky Q1 summary report
We have published our quarterly report for the first quarter of 2020. We mark the outbreak of the COVID-19 virus as a systematic change for most businesses around the world. The immense pressure felt...
View Article