Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials

Recent activities have revealed a series of targeted intrusions by the Iranian-aligned threat group APT35, impacting government and military networks globally.

Recent activities have revealed a series of targeted intrusions by the Iranian-aligned threat group APT35, impacting government and military networks globally.

Detected initially in early 2025, the campaign uses custom malware for infiltration and credential harvesting. The entry point often involves spear-phishing emails containing HTML attachments, which deploy a multi-stage payload upon opening. This process enables the establishment of a foothold in the targeted environment.

The attack chain analysis has shown that weaponized Microsoft Office documents exploiting CVE-2023-23397 are utilized to bypass security protocols. The embedded code downloads a PowerShell stager that retrieves the primary credential-stealer module from a remote command-and-control (C2) server.

Research indicates that this malware impersonates legitimate system processes to avoid detection. It connects to the Windows Security Support Provider Interface (SSPI) to intercept NTLM challenge-response exchanges, capturing hashed credentials in memory. These hashes are sent to the attacker's infrastructure, where hash-cracking and pass-the-hash techniques are used to access privileged accounts on high-value servers.

Recent activities have revealed a series of targeted intrusions by the Iranian-aligned threat group APT35, impacting government and military networks globally.
Yara Mansour · The Levant Herald

The intrusion has notably compromised multiple accounts in military communications networks without triggering conventional intrusion detection systems. The infection mechanism involves a two-stage downloader that first assesses the victim’s environment. If a recognized analysis sandbox is detected, execution is stopped. Otherwise, a base64-encoded second-stage payload is decoded and executed.

The DLL used by the malware implements SSPI hook logic, intercepting credentials and performing HTTP GET requests to the C2 domain over port 443, integrating its traffic with legitimate HTTPS sessions.

Advertisement

This campaign illustrates APT35's advanced tactics in embedding within trusted processes and using native APIs to capture credentials stealthily. Enhanced vigilance and advanced behavioral monitoring are essential to detect such intrusions before critical access is obtained.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories