← Back to list

WezRat Malware: Iranian Hackers Target Israeli Organizations with Advanced Cyber Espionage Tool

Uncovering a new and sophisticated form of malware used by Iranian state-sponsored hacking groups. Known as WezRat, this remote access…

M. Thibaut · 2024-12-01 23:53 · 0 claps · 2.6 min read
#iran #hacker #wezrat #cybersecurity #isreal
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

WezRat Malware: Iranian Hackers Target Israeli Organizations with Advanced Cyber Espionage Tool

Uncovering a new and sophisticated form of malware used by Iranian state-sponsored hacking groups. Known as WezRat, this remote access trojan (RAT) and information stealer has been active since at least September 2023, and is primarily being deployed in cyberattacks against Israeli organizations. The malware, which is equipped with a wide range of malicious capabilities, is designed to perform reconnaissance and execute remote commands on compromised endpoints, making it a potent tool for cyber espionage.

image for illustration from : bankinfosecurity.com

image for illustration from : bankinfosecurity.com

The Nature of WezRat

WezRat has been classified as an advanced cyber tool with the ability to carry out numerous malicious activities. According to cybersecurity firm Check Point, the malware can execute system commands, capture screenshots, upload and download files, perform keylogging, and extract clipboard contents and cookies from browsers. One of its most notable features is that it can operate via separate modules, which are delivered from a command-and-control (C&C) server in the form of Dynamic Link Library (DLL) files. This modular design allows WezRat to evade detection and makes its core component less suspicious to security systems.

The malware is believed to be the work of Cotton Sandstorm, an Iranian hacking group known for conducting politically motivated cyberattacks. The group is also recognized by other aliases, such as Emennet Pasargad and Aria Sepehr Ayandehsazan (ASA).

How WezRat is Deployed

The malware was first identified by both U.S. and Israeli cybersecurity agencies, which described it as a tool designed for information gathering and remote command execution. WezRat is distributed through trojanized versions of legitimate software, specifically Google Chrome installers. These malicious installers, when executed, not only install the legitimate browser but also drop a secondary executable file named Updater.exe (internally labeled as bd.exe), which establishes communication with a C&C server and waits for further instructions.

Check Point’s investigation revealed that WezRat has been primarily distributed to Israeli organizations through phishing emails. The emails, sent on October 21, 2024, appeared to come from the Israeli National Cyber Directorate (INCD) and urged recipients to install an urgent security update for Google Chrome. However, instead of a legitimate update, the installation package carried the malicious payload.

Depiction of the killchain of the RAT WezRat.

Depiction of the killchain of the RAT WezRat.

Malware Capabilities and Evolution

Once executed, WezRat connects to a specific C&C server, such as connect.il-cert[.]net, and uses a “password” parameter to ensure proper functionality. If the password is incorrect, the malware may malfunction or crash. The malware’s capabilities have evolved over time. Early versions of WezRat had hardcoded C&C server addresses and offered basic RAT functionalities. However, the newer variants are more sophisticated and feature additional tools for data exfiltration and monitoring, such as screenshot capture, keylogging, and cookie theft from Chromium-based browsers.

The backend infrastructure of WezRat suggests that its development involves at least two distinct teams. The continuous updates and improvements point to a long-term commitment by the attackers to maintain a highly flexible and evasive tool for cyber espionage.

Conclusion

WezRat is a clear indication of the growing threat posed by state-sponsored actors, specifically Iranian hacking groups, targeting geopolitical adversaries and organizations of strategic interest. The malware’s versatile capabilities make it a potent tool for cyber surveillance and intelligence gathering. Organizations, especially those in Israel or involved in sensitive geopolitical matters, should take immediate action to protect against WezRat and other advanced cyber threats by maintaining up-to-date security measures, staying vigilant against phishing attacks, and employing robust endpoint protections.

jaideàmafaçon : to voyc cyuk !


메타데이터
post_id
ec7d79c061b6
slug
wezrat-malware-iranian-hackers-target-israeli-organizations-with-advanced-cyber-espionage-tool-ec7d79c061b6
url
https://medium.com/@banzance/wezrat-malware-iranian-hackers-target-israeli-organizations-with-advanced-cyber-espionage-tool-ec7d79c061b6
canonical_url
https://medium.com/@banzance/wezrat-malware-iranian-hackers-target-israeli-organizations-with-advanced-cyber-espionage-tool-ec7d79c061b6
author_url
https://medium.com/@banzance
status
ok
fetched_at
2026-07-21 22:11:56