Iranian-aligned threat actor Screening Serpens has escalated its espionage operations by deploying six distinct Remote Access Trojan (RAT) variants. The campaign utilizes sophisticated social engineering via fraudulent recruitment platforms and fake job sites to target high-value technology professionals in the United States, Israel, and the United Arab Emirates. The malware employs advanced obfuscation, diverse Command and Control (C2) infrastructures, and complex persistence mechanisms to facilitate long-term network presence. This evolution indicates a strategic shift toward highly targeted intelligence gathering, aiming to compromise sensitive intellectual property and national security interests through credential harvesting and lateral movement within critical governmental and corporate infrastructures.
-
Incident/Breach Overview
- Targeted campaign focused on high-stakes geopolitical espionage and intelligence gathering.
- Primary victim profiles include high-value technology professionals in the US, Israel, and the UAE.
- Significant evolution of the threat actor's toolkit, moving from legacy tools to six distinct new RAT variants.
-
Attack Vector & Campaign Mechanics
- Initial access facilitated through advanced social engineering and deceptive recruitment lures.
- Deployment of sophisticated fake job websites designed to impersonate legitimate professional services.
- Use of specialized social engineering templates to exploit the professional workflows of high-value targets.
-
Technical Deep Dive: Malware & C2
- Deployment of six new RATs characterized by unique behavioral profiles and advanced obfuscation methods.
- Mapping of complex C2 infrastructure, including specific domain nomenclature and hosting provider patterns.
- Identification of multi-stage persistence mechanisms, lateral movement techniques, and specialized data exfiltration protocols.
-
Impact & Strategic Risk
- Potential for massive strategic intelligence loss regarding US, Israeli, and Emirati national security.
- Targeted theft of sensitive intellectual property within the global technology sector via recruitment lures.
- Risk of sustained, long-term espionage through advanced network persistence and credential harvesting.
-
Indicators of Compromise (IoCs) & Defensive Actions
- Extraction of critical IoCs, including MD5/SHA-256 file hashes and malicious URL patterns.
- Development of YARA rules for robust file-based detection of the new malware family.
- Deployment of Sigma rules to monitor for behavioral indicators of C2 activity and lateral movement.
Related posts
- techjacksolutions.com — Iranian APT 'Screening Serpens' Deploys Six New RAT Variants Targeting US, Israel, and UAE
- Exchange
- Cybersecuritydive
- Cyfirma
- Ctoatncsc
- Hrchiefmagazine
- Jpost
- Cybermagazine
- Sentinelone
- Socdefenders
- Gurucul
- Labs