Security News > 2021 > November > Iran's Lyceum Hackers Target Telecoms, ISPs in Israel, Saudi Arabia, and Africa

Iran's Lyceum Hackers Target Telecoms, ISPs in Israel, Saudi Arabia, and Africa
2021-11-11 00:00

A state-sponsored threat actor allegedly affiliated with Iran has been linked to a series of targeted attacks aimed at internet service providers and telecommunication operators in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a ministry of foreign affairs in Africa, new findings reveal.

The intrusions, staged by a group tracked as Lyceum, are believed to have occurred between July and October 2021, researchers from Accenture Cyber Threat Intelligence group and Prevailion's Adversarial Counterintelligence Team said in a technical report.

The latest revelations throw light on the web-based infrastructure used by Lyceum, over 20 of them, enabling the identification of "Additional victims and provide further visibility into Lyceum's targeting methodology," the researchers noted, adding "At least two of the identified compromises are assessed to be ongoing despite prior public disclosure of indicators of compromise."

Believed to be active since 2017, Lyceum is known to target sectors of strategic national importance for purposes of cyber espionage, while also retooling its arsenal with new implants, and expanding its sights to include ISPs and government agencies.

ACTI and PACT also said it located beaconing from a reconfigured or potentially a new Lyceum backdoor in late October 2021 originating from a telecommunications company in Tunisia and an MFA in Africa, indicating that the operators are actively updating their backdoors in light of recent public disclosures and attempting to bypass detection by security software.

"Lyceum will likely continue to use the Shark and Milan backdoors, albeit with some modifications, as the group has likely been able to maintain footholds in victims' networks despite public disclosure of associated with its operations," the researchers said.


News URL

https://thehackernews.com/2021/11/irans-lyceum-hackers-target-telecoms.html