{"id":457683,"date":"2022-08-24T13:22:18","date_gmt":"2022-08-24T11:22:18","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=457683"},"modified":"2022-08-24T13:27:58","modified_gmt":"2022-08-24T11:27:58","slug":"iranian-malware-steals-user-data-from-gmail-yahoo-and-microsoft-outlook","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/457683-iranian-malware-steals-user-data-from-gmail-yahoo-and-microsoft-outlook.html","title":{"rendered":"Iranian malware steals user data from Gmail, Yahoo!, and Microsoft Outlook"},"content":{"rendered":"<p>A malicious actor known as Charming Kitten \u2014 backed by the Iranian government \u2014 has developed a new malware tool that pulls user data from victims&#8217; Gmail, Yahoo!, and Microsoft Outlook accounts.<\/p>\n<p>According to a <strong><a href=\"https:\/\/blog.google\/threat-analysis-group\/new-iranian-apt-data-extraction-tool\/\" target=\"_blank\" rel=\"noopener\">blog post<\/a><\/strong> from Google&#8217;s Threat Analysis Group (TAG), the malicious tool has been used against fewer than two dozen email accounts in Iran, with the first example dating back to 2020.<\/p>\n<p>The tool, which TAG dubbed Hyperscrape, was first discovered in December 2021, and the threat actor behind the software is believed to be associated with Iran&#8217;s Revolutionary Guard Corps.<\/p>\n<p>Charming Kitten has a history of carrying out espionage in line with the interests of the Iranian government.<\/p>\n<p>Google TAG researcher Ajax Bash explained that the attack requires the victim&#8217;s account credentials to pull data.<\/p>\n<p>&#8220;Hyperscrape requires the victim&#8217;s account credentials to run using a valid, authenticated user session the attacker has hijacked, or credentials the attacker has already acquired,&#8221; Bash said.<\/p>\n<p>The tool includes functions to download and extract the contents of a victim&#8217;s inbox, and it deletes security emails from Google sent to notify the victim of suspicious activity.<\/p>\n<p>Hyperscrape goes so far as to open and download unread emails and then marks them as unread again once it has extracted the information.<\/p>\n<p>Bash emphasised the tool is not notable for its technical sophistication but rather its effectiveness in achieving Charming Kitten&#8217;s objectives.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/457663-former-twitter-executive-blows-lid-off-egregious-security-problems.html\" target=\"_blank\" rel=\"noopener\">Former Twitter executive blows lid off &#8220;egregious&#8221; security problems<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Charming Kitten, a threat actor group backed by the Iranian government, has stolen data from victims since 2020.<\/p>\n","protected":false},"author":341076,"featured_media":457703,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[80855,407,80857,801,123,17198,73190,2744],"class_list":["post-457683","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-charming-kitten","tag-gmail","tag-hyperscrape","tag-malware","tag-microsoft","tag-outlook","tag-threat-analysis-group-tag","tag-yahoo"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/457683"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=457683"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/457683\/revisions"}],"predecessor-version":[{"id":457813,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/457683\/revisions\/457813"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/457703"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=457683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=457683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=457683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}