London Daily

Focus on the big picture.
Wednesday, May 13, 2026

Undiscovered Iranian ‘Operation GhostShell’ state-sponsored cyberthreat: report

Undiscovered Iranian ‘Operation GhostShell’ state-sponsored cyberthreat: report

A state-sponsored cyber-espionage campaign has been targeting companies globally including those in the U.S., a new report says.

The cyberattacks were carried out by a newly discovered Iranian group dubbed MalKamak, cybersecurity firm Cybereason said in a new report.

The group has been operating "under the radar" since at least 2018, Cybereason said.

Anonymous computer hacker sitting in front of a virtual screen.


In July, Cybereason's investigative teams responded to Operation GhostShell, a "highly-targeted cyber espionage" campaign aiming to steal sensitive information from global aerospace and telecommunications companies mainly in the Middle East but also companies in the U.S., Europe and Russia.

During the investigation, Cybereason’s Nocturnus Team uncovered a previously undocumented Remote Access Trojan, or RAT, which was employed as the primary espionage tool.

A Trojan horse, or Trojan, is malicious code that appears legitimate but is designed to damage a computer network or steal sensitive data. A RAT typically allows the attacker to gain unauthorized remote access for covert surveillance.

"We witnessed the evolution of a malware that started very simple and over time turned into a sophisticated espionage tool," Assaf Dahan, senior director, head of threat research at Cybereason, told FOX Business.

"The RAT itself can conduct reconnaissance and collect information about the users and infected hosts," Dahan said.

The RAT evaded antivirus tools by using Dropbox as cover.

The Dropbox logo is seen in this illustration photo in 2017. The MalKamak threat group allegedly created Dropbox accounts for their command and control purposes.


"The MalKamak threat group … created Dropbox accounts and used them for their command-and-control purposes," according to Dahan.

"Essentially, they used Dropbox to carry out their operations right under the noses of security professionals. This is a clever way to hide in plain sight since Dropbox is a trusted brand -- and traffic to a legitimate site usually will not raise suspicions of certain security products and analysts," Dahan said.

The authors of the malware also implemented a kill function that instructs the malware to delete itself if they believe their operation might be jeopardized.

"It is very likely MalKamak exfiltrated [stole] hundreds of terabytes of data since launching their campaigns in 2018," Dahan said.

The Iranian group behind the attack is possibly connected to other Iranian state-sponsored actors.

"When we compared MalKamak to known Iranian groups, we did find some potentially interesting connections to other Iranian state-sponsored threat actors," Dahan said, adding, however, that this is still speculation and they need more time to make a definite connection.

Cyber security IT engineer working on protecting network against cyberattack from hackers on internet. Recently, an Iranian group called MalKamak has been carrying out cyberattacks.


But the aim is the same: the aerospace and telecommunications sectors are prime targets for Iran, Chris Morgan, senior cyber threat intelligence analyst at Digital Shadows, a San Francisco-based cybersecurity firm, told FOX Business.

"Obtaining sensitive information related to these sectors … could provide Iran with a strategic advantage, which was likely the overall goal of the GhostShell campaign," Morgan said.

Newsletter

Related Articles

0:00
0:00
Close
The Great Western Exit: Why Best Citizens Are Fleeing the Rich World [PODCAST]
The New Robber Barons of Intelligence: Are AI Bosses More Powerful Than Rockefeller?
The End of the Old Order [Podcast]
Britain’s Democracy Is Now a Costume
The AI Gold Rush Is Coming for America’s Last Open Spaces [Podcast]
The Pentagon’s AI Squeeze: Eight Tech Giants Get In, Anthropic Gets Shut Out [Podcast]
The War Map: Professor Jiang’s Dark Theory of Iran, Trump, China, Russia, Israel, and the Coming Global Shock [Podcast]
Labour Is No Longer a National Party [Podcast]
AI Isn’t Stealing Your Job. It’s Dismantling It Piece by Piece.
Lawyers vs Engineers: Why China Builds While America Litigates [Podcast]
Churchill’s Glass: The Drunk, the Doctor, and the Myth Britain Refuses to Sober Up From
Apple issues an unusual warning: this is how your iPhone can be hacked without you doing anything
Kennedy’s Quiet War on Antidepressants Sparks Alarm Across America’s Medical Establishment
The Met Gala Meets the Age of Billionaire Backlash
Russian Oligarch’s Superyacht Crosses Hormuz via Iran-Controlled Route
Gunfire Disrupts White House Correspondents’ Dinner as Trump Is Evacuated
A Leak, a King, and a Fracturing Alliance
Inside the Gates Foundation Turmoil: Layoffs, Scrutiny, and the Cost of Reputational Risk
UK Biobank Breach Exposes Health Data of 500,000, Listed for Sale on Chinese Platform
KPMG Cuts Around 10% of US Audit Partners After Failed Exit Push
French Police Probe Suspected Weather-Data Tampering After Unusual Polymarket Bets on Paris Temperatures
CATL Unveils Revolutionary EV Battery Tech: 1000 km Range and 7-Minute Charging Ahead of Beijing Auto Show
Crypto Scammers Capitalize on Maritime Chaos Near the Strait of Hormuz: A Rising Threat to Shipping Companies
Changi Airport: How Singapore Engineered the World’s Most Efficient Travel Experience
Power Dynamics: Apple’s Leadership Shakeup, Geopolitical Risks in the Strait of Hormuz, and Europe's Energy Strategy Amidst Global Challenges
Apple's Leadership Transition: Can New CEO John Ternus Navigate AI Challenges and Geopolitical Pressures?
Italy’s €100K Tax Gambit: Europe’s Soft Power Tax Haven
News Roundup
Microsoft lost 2.5 millions users (French government) to Linux
Privacy Problems in Microsoft Windows OS
News roundup
Péter András Magyar and the Strategic Reset of Hungary
Hungary After the Landslide — A Strategic Reset in Europe
Meghan Markle Plans Exclusive Women-Focused Retreat During Australia Visit
Starmer and Trump Hold Strategic Talks on Securing Strait of Hormuz Amid Rising Tensions
Unofficial Australia Visit by Prince Harry and Meghan Expected to Stir Tensions with Royal Circles
Pipeline Attack Cuts Significant Share of Saudi Arabia’s Oil Export Capacity
UK Stocks Rise on Ceasefire Momentum and Renewed Focus on Diplomacy
UK to Hold Further Strategic Talks on Strait of Hormuz Security
Starmer Voices Frustration as Global Tensions Drive Up UK Energy Costs
UK Students Voice Concern Over Proposal for Automatic Military Draft Registration
Rising Volatility Drives Uncertainty in UK Fuel and Petrol Prices
UK Moves to Deploy ‘Skyhammer’ Anti-Drone System to Strengthen Airspace Defense
New Analysis Explores UK Budget Mechanics in ‘Behind the Blue’ Feature
Man Arrested After Four Die in Channel Crossing Tragedy
UK Tightens Immigration Framework with New Sponsor Rules and Fee Increases
UK Foreign Secretary Highlights Impact of Intensified Strikes in Lebanon
UK Urges Inclusion of Lebanon in US-Iran Ceasefire Framework
UK Stocks Ease as Ceasefire Doubts in Middle East Weigh on Investor Confidence
UK Reassesses Cloud Strategy Amid Criticism Over Limited Support Measures
×