APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials
Recent activities have revealed a series of targeted intrusions by the Iranian-aligned threat group APT35, impacting government and military networks globally.
Recent activities have revealed a series of targeted intrusions by the Iranian-aligned threat group APT35, impacting government and military networks globally.
Detected initially in early 2025, the campaign uses custom malware for infiltration and credential harvesting. The entry point often involves spear-phishing emails containing HTML attachments, which deploy a multi-stage payload upon opening. This process enables the establishment of a foothold in the targeted environment.
The attack chain analysis has shown that weaponized Microsoft Office documents exploiting CVE-2023-23397 are utilized to bypass security protocols. The embedded code downloads a PowerShell stager that retrieves the primary credential-stealer module from a remote command-and-control (C2) server.
Research indicates that this malware impersonates legitimate system processes to avoid detection. It connects to the Windows Security Support Provider Interface (SSPI) to intercept NTLM challenge-response exchanges, capturing hashed credentials in memory. These hashes are sent to the attacker's infrastructure, where hash-cracking and pass-the-hash techniques are used to access privileged accounts on high-value servers.
Recent activities have revealed a series of targeted intrusions by the Iranian-aligned threat group APT35, impacting government and military networks globally.
The intrusion has notably compromised multiple accounts in military communications networks without triggering conventional intrusion detection systems. The infection mechanism involves a two-stage downloader that first assesses the victim’s environment. If a recognized analysis sandbox is detected, execution is stopped. Otherwise, a base64-encoded second-stage payload is decoded and executed.
The DLL used by the malware implements SSPI hook logic, intercepting credentials and performing HTTP GET requests to the C2 domain over port 443, integrating its traffic with legitimate HTTPS sessions.
This campaign illustrates APT35's advanced tactics in embedding within trusted processes and using native APIs to capture credentials stealthily. Enhanced vigilance and advanced behavioral monitoring are essential to detect such intrusions before critical access is obtained.
Based on reporting by Cyber Security News.




