CTI Analysis: Malicious Email Campaign

Sept. 2, 2025, 9:43 a.m.

Description

An Iran-nexus spear-phishing campaign masquerading as the Omani Ministry of Foreign Affairs targeted global governments in August 2025. Attributed to Iranian-aligned operators linked to the Homeland Justice group and MOIS, the campaign used compromised mailboxes to send emails with malicious Microsoft Word attachments. The documents contained VBA macros that decoded and deployed malware payloads. The multi-wave operation targeted diplomatic and governmental entities across multiple regions, including the Middle East, Africa, Europe, Asia, and the Americas. The campaign utilized social engineering lures, anti-analysis techniques, and a reconnaissance-focused malware called sysProcUpdate. The attackers aimed to gain initial access, map internal networks, and prepare for further exploitation in diplomatic and industrial organizations.

Date

  • Created: Sept. 2, 2025, 8:58 a.m.
  • Published: Sept. 2, 2025, 8:58 a.m.
  • Modified: Sept. 2, 2025, 9:43 a.m.

Indicators

  • 80e9105233f9d93df753a43291c2ab1a010375357db9327f9fe40d184f078c6b
  • f0ba41ce46e566f83db1ba3fc762fd9b394d12a01a9cef4ac279135e4c1c67a9
  • b2c52fde1301a3624a9ceb995f2de4112d57fcbc6a4695799aec15af4fa0a122
  • 76fa8dca768b64aefedd85f7d0a33c2693b94bdb55f40ced7830561e48e39c75
  • 3d6f69cc0330b302ddf4701bbc956b8fca683d1c1b3146768dcbce4a1a3932ca
  • 3ac8283916547c50501eed8e7c3a77f0ae8b009c7b72275be8726a5b6ae255e3
  • 20e7b9dcf954660555d511a64a07996f6178f5819f8501611a521e19fbba74b0
  • 2c92c7bf2d6574f9240032ec6adee738edddc2ba8d3207eb102eddf4ab963db0
  • 1c16b271c0c4e277eb3d1a7795d4746ce80152f04827a4f3c5798aaf4d51f6a1
  • 1883db6de22d98ed00f8719b11de5bf1d02fc206b89fedd6dd0df0e8d40c4c56
  • 05d8f686dcbb6078f91f49af779e4572ba1646a9c5629a1525e8499ab481dbf2
  • 03828aebefde47bca0fcf0684ecae18aedde035c85f9d39edd2b7a147a1146fa
  • 02ccc4271362b92a59e6851ac6d5d2c07182064a602906d7166fe2867cc662a5
  • https://screenai.online/Home/
  • screenai.online

Attack Patterns

Additional Informations

  • Government
  • Malawi
  • Rwanda
  • Ethiopia
  • Mongolia
  • Nigeria
  • Hungary
  • Sweden
  • Austria
  • Qatar
  • Colombia
  • Korea, Democratic People's Republic of
  • Bangladesh
  • Jordan
  • Korea, Republic of
  • Netherlands
  • Argentina
  • Spain
  • Italy
  • Thailand
  • Peru
  • Canada
  • Japan
  • France
  • Germany
  • Romania
  • Oman
  • Bahrain
  • Israel
  • Brazil