https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures


cyber globe

Cybereason Finds New Malware in Iranian Espionage Campaigns

  • Written by Edward Gately
  • February 2, 2022

Cybereason has discovered previously unidentified malware variants being leveraged in two separate Iranian state-sponsored cyber espionage operations targeting a wide range of organizations in multiple global regions.

Moses Staff is deploying ransomware against targets to inflict damage and hamper forensic investigations, while Phosphorus is joining-forces to inflict global damage partnering with the recently documented Memento ransomware group.

Moses Staff’s list of victims includes multiple countries and regions. Among them are Israel, Italy, India, Germany, Chile, Turkey, United Arab Emirates (UAE) and the United States.

Phosphorus has been spotted attacking research facilities in multiple regions such as the United States, Europe and the Middle East. The group is known to be behind multiple cyber espionage and offensive cyber attacks, operating in the interest of the Iranian regime, leveraging cyberwarfare in accordance with Iran’s geopolitical interests.

Assaf Dahan is Cybereason‘s senior director and head of threat research.

“There have been multiple reports about attacks carried out by these groups that were successful,” he said. “The damages can be quite severe if you take the consequences of such attacks into account. There are direct damages caused by the deployment of ransomware and the encryption of the files, which can jeopardize business continuity and prevent organizations from accessing their data, not to mention the damage caused by the act of stealing sensitive data. That data can be later used to facilitate further attacks or used for espionage purposes. Additionally, we have to take into account the leaking of the data that can cause huge reputational damage to the victims and even open the victims to lawsuits.”

Cybereason recommends a three-step approach for organizations to protect themselves.

“First, defenders and security teams should study our reports and extract all the indicators that we provide,” Dahan said. “We recommend focusing on understanding the modus operandi of these attackers and making sure that they can proactively hunt for signs of compromise, as detailed in our reports. Second, we recommend patching all endpoints, and especially critical servers, since the root cause of most of the attacks lies in unpatched systems (consider Microsoft Exchange servers, log4J and VPN clients). Finally, defenders should have a wholistic XDR platform that can detect correlated events from all parts of the network.”

 

Tags:

Edward Gately

Edward Gately

As news editor, Edward Gately covers cybersecurity, new channel programs and program changes, M&A and other IT channel trends. Prior to Informa, he spent 26 years as a newspaper journalist in Texas, Louisiana and Arizona.

Related Content

  • MSP growth
    MDF and the Channel: What Happened to the Customer?
  • Making Waves
    7 Channel People Making Waves This Week at Google Cloud, SAP, AWS Marketplace, More
  • Top 20
    Top 20 Stories in January: CPaaS List, Sexual Harassment, Windstream Channel Chief
  • MDR Concept
    How MDR Helps MSPs Navigate an Unfriendly Cyber Landscape

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Zero Trust World 2023: ThreatLocker Unleashes Ops Threat-Detection Tool

February 2, 2023

Telecom-IT Layoff Tracker 2023: Cisco, RingCentral, Microsoft, 8×8, Sophos, More

February 2, 2023

January’s Tech Layoff Scourge: Deep Dive Into Channel Impact

February 2, 2023

Industry Perspectives

View all

How to Break Through the Growth Ceiling

February 1, 2023

5 Things to Look for in a UC Partner

January 31, 2023

The Benefits of Hiring an Investment Bank

January 30, 2023

Webinars

View all

Next-Generation MSP Platform: The Building Blocks for Your Business

February 15, 2023

How To Boost Your Business With White-Label UCaaS

February 28, 2023

Security Secrets of the MSP 501: How to Be a Cyber Leader in 2023

December 15, 2022
  • 1

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 117: Cato Networks, Video Killed the Podcast Stars

Retired Astronaut Capt. Scott Kelly Previews His CP Expo Keynote

December 21, 2022

Fusion Connect Eyes Future with Intrado UC, Managed Network Customers

September 23, 2022

RingCentral Focused on Hybrid Work, Microsoft Teams, Other Integrations

September 23, 2022

Twitter

ChannelFutures

.@broadvoice appoints a channel vet as new program leader. Before joining the company, he had risen through the ran… twitter.com/i/web/status/1…

February 2, 2023
ChannelFutures

More activity over at @Pax8 (which just hired @RobTRae): the #cloud marketplace firm has purchased @BamBoomCloud.… twitter.com/i/web/status/1…

February 2, 2023
ChannelFutures

.@SamsungMobile launches #GalaxyS23 phones, new #GalaxyBook3Ultra at Samsung Unpacked. dlvr.it/ShrW8G https://t.co/DloltwdMsE

February 2, 2023
ChannelFutures

The new partnership between Channel Futures and @ITExchangeNet is poised to benefit the partner community.… twitter.com/i/web/status/1…

February 2, 2023
ChannelFutures

.@JuniperNetworks announces transition to “solution building outcomes," addresses pain points around quoting, prici… twitter.com/i/web/status/1…

February 2, 2023
ChannelFutures

Day 1 of #ZTW23: @ThreatLocker hopes attendees walk away smarter about #zero trust and cybersecurity.… twitter.com/i/web/status/1…

February 2, 2023
ChannelFutures

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them dlvr.it/ShpCHp https://t.co/Av6eJmYnnF

February 1, 2023
ChannelFutures

Frost Radar: North American UCaaS Market, 2022 dlvr.it/ShpBhh https://t.co/KhiTCSoGRH

February 1, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X