London Daily

Focus on the big picture.
Friday, Apr 03, 2026

Undiscovered Iranian ‘Operation GhostShell’ state-sponsored cyberthreat: report

Undiscovered Iranian ‘Operation GhostShell’ state-sponsored cyberthreat: report

A state-sponsored cyber-espionage campaign has been targeting companies globally including those in the U.S., a new report says.

The cyberattacks were carried out by a newly discovered Iranian group dubbed MalKamak, cybersecurity firm Cybereason said in a new report.

The group has been operating "under the radar" since at least 2018, Cybereason said.

Anonymous computer hacker sitting in front of a virtual screen.


In July, Cybereason's investigative teams responded to Operation GhostShell, a "highly-targeted cyber espionage" campaign aiming to steal sensitive information from global aerospace and telecommunications companies mainly in the Middle East but also companies in the U.S., Europe and Russia.

During the investigation, Cybereason’s Nocturnus Team uncovered a previously undocumented Remote Access Trojan, or RAT, which was employed as the primary espionage tool.

A Trojan horse, or Trojan, is malicious code that appears legitimate but is designed to damage a computer network or steal sensitive data. A RAT typically allows the attacker to gain unauthorized remote access for covert surveillance.

"We witnessed the evolution of a malware that started very simple and over time turned into a sophisticated espionage tool," Assaf Dahan, senior director, head of threat research at Cybereason, told FOX Business.

"The RAT itself can conduct reconnaissance and collect information about the users and infected hosts," Dahan said.

The RAT evaded antivirus tools by using Dropbox as cover.

The Dropbox logo is seen in this illustration photo in 2017. The MalKamak threat group allegedly created Dropbox accounts for their command and control purposes.


"The MalKamak threat group … created Dropbox accounts and used them for their command-and-control purposes," according to Dahan.

"Essentially, they used Dropbox to carry out their operations right under the noses of security professionals. This is a clever way to hide in plain sight since Dropbox is a trusted brand -- and traffic to a legitimate site usually will not raise suspicions of certain security products and analysts," Dahan said.

The authors of the malware also implemented a kill function that instructs the malware to delete itself if they believe their operation might be jeopardized.

"It is very likely MalKamak exfiltrated [stole] hundreds of terabytes of data since launching their campaigns in 2018," Dahan said.

The Iranian group behind the attack is possibly connected to other Iranian state-sponsored actors.

"When we compared MalKamak to known Iranian groups, we did find some potentially interesting connections to other Iranian state-sponsored threat actors," Dahan said, adding, however, that this is still speculation and they need more time to make a definite connection.

Cyber security IT engineer working on protecting network against cyberattack from hackers on internet. Recently, an Iranian group called MalKamak has been carrying out cyberattacks.


But the aim is the same: the aerospace and telecommunications sectors are prime targets for Iran, Chris Morgan, senior cyber threat intelligence analyst at Digital Shadows, a San Francisco-based cybersecurity firm, told FOX Business.

"Obtaining sensitive information related to these sectors … could provide Iran with a strategic advantage, which was likely the overall goal of the GhostShell campaign," Morgan said.

Newsletter

Related Articles

0:00
0:00
Close
Trump’s Strategic Pressure on UK Seen as Push for Stronger Alignment and Fairer Terms
UK Focuses on Trade Finance to Secure Critical Materials for Defence and Energy Sectors
Majority of UK Businesses Hit by Middle East Conflict While Confidence Holds Firm
UK Royal Navy Faces Renewed Scrutiny as Debate Intensifies Over Capability and Readiness
Reform UK Faces Mounting Distractions as Policy Agenda Struggles to Gain Traction
Investigation Launched Into Northern Cyprus IVF Clinics After UK Families Receive Incorrect Sperm
International Meeting Issues Unified Call to Safeguard Navigation Through Strait of Hormuz
Potential Strait of Hormuz Closure Raises Concerns Over UK Food and Medicine Supply Chains
UK Leads Coalition of Over Forty Nations Urging Iran to Reopen Strait of Hormuz
UK Secures Tariff-Free Access for Medicines in Landmark US Pharma Trade Agreement
King Charles III Invited to Address Joint Session of U.S. Congress in Rare Diplomatic Honor
Debate Grows Over Whether Expanded North Sea Drilling Can Reduce UK Energy Bills
UK Faces Heightened Risk of Jet Fuel Shortages, Airline Chief Warns
UK Ends Police Investigations into Lawful Social Media Posts After Review Finds Overreach
Abramovich Moves to Establish Charity for Frozen Chelsea Sale Proceeds Amid UK Dispute
Starmer Reaffirms NATO Commitment While Responding to Trump’s Strategic Critique
UK Aid Reductions Raise Fears of Severe Human Impact Across Parts of Africa
UK Signals Renewed Push for EU Cooperation as Iran Conflict Reshapes Security Landscape
Bank of England Signals Caution as Bailey Advises Markets Against Expecting Rate Hikes
UK to Convene Global Coalition to Restore Shipping Through Strait of Hormuz
Trump Signals Possible NATO Reassessment, Emphasizes Stronger U.S. Strategic Autonomy
Australia Joins British-Led Efforts to Reopen Strait of Hormuz Amid Escalating Tensions
King Charles Plans US State Visit as UK Strengthens Ties with Trump Leadership
UK Regulator Launches Investigation Into Microsoft’s Business Software Practices
Kanye West Set for High-Profile Return to UK Stage at Wireless Festival
Trump Presses Europe to Strengthen Commitment as Iran Conflict Escalates
UK to Deploy Additional Troops to Middle East Amid Rising Regional Tensions
UK Authorities Face Claims of Heavy-Handed Measures in Monitoring Released Pro-Palestine Activists
Trump Calls on UK to Secure Its Own Energy as Iran Conflict Intensifies
Nigel Farage Declines Invitation to UK Conservative Conference Led by Liz Truss
Trump Warns Allies to Take Responsibility as Rift Deepens with UK and France Over Iran Conflict
How Britain’s Prime Minister Controls U.S. Bomber Access in Escalating Iran Conflict
Trump Urges Allies to Secure Their Own Oil Supplies as Hormuz Crisis Disrupts Global Energy
Russia Expels British Diplomat as UK Pushes Back Against Pressure
White House App Faces Scrutiny After Claims of Continuous User Location Tracking
BBC Faces Scrutiny Over Allegations of Paid Content Linked to Saudi Arabia
UK-France Coastal Patrol Agreement Nears Breakdown Amid Migration Pressures
UK Police Detain Pro-Palestine Activist Again Weeks After Bail Release
FTSE 100 Advances as Energy and Mining Shares Gain Amid Middle East Tensions
Eli Lilly Seeks UK Pricing Deal to Unlock Renewed Pharmaceutical Investment
Three Arrested in UK After Massive Cocaine Haul Discovered Hidden in Banana Shipment
UK Fuel Prices Poised for Further Surge Amid Global Energy Pressures
Apple Subsidiary Penalized by UK Authorities for Breach of Moscow Sanctions
Western Allies Intensify Coordinated Sanctions Strategy Against Russia
UK Lawmakers Face Criticism Over Renewed Push for Social Media Restrictions
Starmer Signals UK Crackdown on Addictive Social Media Features
Rising Costs Push One in Five UK Hospitality Businesses to the Brink of Closure
Man Arrested on Suspicion of Attempted Murder After Car Strikes Pedestrians in UK, Injuring Seven
Escalating Conflict Involving Iran Tightens Fiscal Pressures and Highlights UK Economic Vulnerabilities
UK Moves to Confront Russian ‘Shadow Fleet’ Operating in Its Waters
×