Campaigns
 Decoding the Spear-Phishing Tactics of SEABORGIUM and TA453 in the UK

Decoding the Spear-Phishing Tactics of SEABORGIUM and TA453 in the UK

SEABORGIUMTA453RussiaIranAPT 42Calisto
SEABORGIUM and TA453 are Russia-based and Iran-based threat actors conducting spear-phishing campaigns targeting organizations and individuals in the U.K. and other areas of interest. They target various sectors, including academia, defense, governmental organizations, and NGOs, using personalized phishing emails to compromise the victims' credentials and gain access to sensitive information.

Indicators of Compromise

nco2.live
gettogether.quest
continuetogo.me
css-ethz.ch
tinyurl.ink
mailer-daemon-message.co
check.id
mailer-daemon.me
bnt2.live
mailer-daemon.live
profilepic.site
local0.info
mailer-daemon.online
mailer-daemon.org
litby.us
mailer-daemon.net
mailerdaemon.me
de-ma.online
office-updates.info
cija-drive.com
docs-shared.online
protection-office.live
hypertextttech.com
cache-dns-forwarding.com
document-forwarding.com
drive-control.com
nonviolent-conflict-service.com
onlinecloud365.live
y-ml.co
drive-globalordnance.com
lk-nalog-gov.ru
pdf-docs.online
hd-docs-share.com
attach-update.com
guard-checker.com
protection-web-app.com
documents-cloud.com
live-identifier.com
yandx-online.cloud
botguard-web.com
cache-pdf.online
response-filter.com
word-yand.live
dns-cache.online
threatcenterofreaserch.com
drive-information.com
redir-document.com
cache-dns-preview.com
pdf-cache.com
selector-drafts.online
as-mvd.ru
goo-link.online
checker-bot.com
document-preview.com
online-document.live
proton-view.online
apicomcloud.com
hd-centre-drive.com
botguard-checker.com
response-redir.com
docs-collector.com
documents-preview.com
proton-viewer.com
docs-cache.online
proxycrioisolation.com
drive-previewer.com
umo-drive.com
blueskynetwork-shared.com
cache-docs.com
relogin-dashboard.online
office365-online.live
doc-viewer.com
protectionmail.online
webresources.live
goo-ink.online
antibots-service.com
goweb-protect.com
drive-defender.com
dns-challenge.com
protectedshields-storage.com
umopl-drive.com
drive-us.online
office-protection.online
docs-info.com
documents-online.live
dns-cookie.com
cija-docs.com
mvd-redir.ru
proton-reader.com
encompass-shared.com
share-drive-ua.com
pdf-shared.online
cloud-mail.online
preview-docs.online
challenge-identifier.com
docs-viewer.online
safe-connection.online
docs-cache.com
mail-docs.online
document-sender.com
docs-drive.online
soaringeagle-drive.com
accounts.hypertexttech.com
documents-forwarding.com
dtgruelle-drive.com
docs-storage-ltd.com
land-of-service.com
hypertexttech.com
nonviolent-conflict-storage.com
documents-cloud.online
transfer-record.com
secureoffice.live
disk-previewer.com
dtgruelle-us.com
protection-checklinks.xyz
drive-global-ordnance.com
blueskynetwork-drive.com
cache-dns.com
proton-pdf.online
threatcenterofresearch.com
document-view.live
cloud-drive.live
docs-shared.com
webview-service.com
pdf-cloud.online
mvd-cloud.ru
safelinks-protect.live
docs-view.online
cache-services.live
sangrail-share.com
attach-docs.com
response-mvd.ru
docs-info.online
protection-link.online
goweb-service.com
documents-view.live
sangrail-ltd.com
online365-office.com
network-storage-ltd.com
cloud-storage.live
docs-web.online
documents-pdf.online
encompass-drive.com
online-storage.live
umopl.com
proton-docs.com
cloud-safety.online
cloud-us.online
filter-bot.com
storage-service.online
file-milgov.systems
online-word.com
officeonline365.live
default-dns.online
protect-link.online
cache-pdf.com
hypertextteches.com
dns-mvd.ru
pdf-cache.online
preview-docs.com
pdf-forwarding.online
global-ordnance-drive.com
cloud-docs.com
document-guard.com
document-online.live
docs-forwarding.online
allow-access.com
drive-share.live
access-confirmation.com
drive-docs.com
document-share.live
safe-proof.com

APT Groups2

CallistoRussian Federation
SEABORGIUMTA446StarBlizzardGOSSAMERBEARCOLDRIVERGOSSAMER BEARStar BlizzardBlueCharlie
APT42Iran, Islamic Republic of

<div>APT42 -also known as Crooked Charms and TA453– is a cyber espionage group linked to Iran. The group is allegedly affiliated with the Islamic Revolutionary Guard Corps (IRGC) Intelligence Organization (IRGC-IO) and operates behalf of them. The group seems mainly focused on spearphishing attacks, which is a type of phishing attack targeting individuals or organizations known as high-profile or in a specific role—using impersonation to look like a trusted person during its attacks separates the group from other Iranian APT groups.</div>

CALANQUEUNC788APT 42

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Recommended customer actions

The techniques used by the actor and described in the “Observed actor activity” section can be mitigated by adopting the security considerations provided below:

  • Check your Office 365 email filtering settings to ensure you block spoofed emails, spam, and emails with malware.
  • Configure Office 365 to disable email auto-forwarding.
  • Use the included indicators of compromise to investigate whether they exist in your environment and assess for potential intrusion.
  • Review all authentication activity for remote access infrastructure, with a particular focus on accounts configured with single factor authentication, to confirm authenticity and investigate any anomalous activity.
  • Require multifactor authentication (MFA) for all users coming from all locations including perceived trusted environments, and all internet-facing infrastructure–even those coming from on-premises systems.
  • Leverage more secure implementations such as FIDO Tokens, or Microsoft Authenticator with number matching. Avoid telephony-based MFA methods to avoid risks associated with SIM-jacking.
For Microsoft Defender for Office 365 Customers:
  • Use Microsoft Defender for Office 365 for enhanced phishing protection and coverage against new threats and polymorphic variants.
  • Enable Zero-hour auto purge (ZAP) in Office 365 to quarantine sent mail in response to newly acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.
  • Configure Defender for Office 365 to recheck links on click. Safe Links provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages, other Office applications such as Teams, and other locations such as SharePoint Online. Safe Links scanning occurs in addition to the regular anti-spam and anti-malware protection in inbound email messages in Exchange Online Protection (EOP). Safe Links scanning can help protect your organization from malicious links that are used in phishing and other attacks.
  • Use the Attack Simulator in Microsoft Defender for Office 365 to run realistic, yet safe, simulated phishing and password attack campaigns within your organization. Run spear-phishing (credential harvest) simulations to train end-users against clicking URLs in unsolicited messages and disclosing their credentials.

Detections

Intelligence gathered by the Microsoft Threat Intelligence Center (MSTIC) is used within Microsoft security products to provide protection against associated actor activity.

Microsoft Defender for Office 365

Microsoft Defender for Office offers enhanced solutions for blocking and identifying malicious emails. Signals from Microsoft Defender for Office inform Microsoft 365 Defender, which correlate cross-domain threat intelligence to deliver coordinated defense, when this threat has been detected. These alerts, however, can be triggered by unrelated threat activity. Example alerts:

A potentially malicious URL click was detected
Email messages containing malicious URL removed after delivery
Email messages removed after delivery
Email reported by user as malware or phish
Microsoft 365 Defender
Aside from the Microsoft Defender for Office 365 alerts above, customers can also monitor for the following Microsoft 365 Defender alerts for this attack. Note that these alerts can also be triggered by unrelated threat activity. Example alerts:

Suspicious URL clicked
Suspicious URL opened in web browser
User accessed link in ZAP-quarantined email
Microsoft 365 Defender customers should also investigate any “Stolen session cookie was used” alerts that would betriggered for adversary-in-the-middle (AiTM) attacks.

Microsoft Defender SmartScreen
Microsoft Defender SmartScreen has implemented detections against the phishing domains represented in the IOC section above.

Observed Countries34

AL (505)
AT (795)
BA (416)
BE (374)
BG (750)
CH (535)
DE (152)
DK (551)
ES (302)
FI (124)
FR (500)
GB (453)
GR (154)
HR (194)
HU (371)
IS (77)
IT (461)
LT (57)
LU (752)
LV (476)
MC (929)
MD (883)
ME (865)
MK (210)
NO (985)
PT (685)
RO (953)
RS (800)
SE (951)
SI (666)
SK (38)
TR (319)
UA (114)
US (677)