- May 4, 2019
Deep Instinct researchers have recently identified unusual – and dangerous – activity within the environment of one of our customers, an infrastructure and construction company in the Southern U.S. After close analysis, we found that an Iranian APT was attempting to compromise an Exchange server and that seven attempts were made in total, each of which was immediately prevented by Deep Instinct.
Due to the discovery, Deep Instinct was able to find additional new malware variants and TTPs related to the threat actor. Notably, installation of a root certificate and an attempt to blend malicious traffic with legitimate traffic.
A full analysis of the event follows.
Iranian Threat Actor & Mass Exploitation Tools | Deep Instinct
Deep Instinct researchers found an Iranian APT was attempting to compromise an Exchange server. Learn more about how we found additional new malware variants & related TTPs.