WezRat Malware: Iranian Hackers Target Israeli Organizations with Advanced Cyber Espionage Tool
Uncovering a new and sophisticated form of malware used by Iranian state-sponsored hacking groups. Known as WezRat, this remote access…
WezRat Malware: Iranian Hackers Target Israeli Organizations with Advanced Cyber Espionage Tool
Uncovering a new and sophisticated form of malware used by Iranian state-sponsored hacking groups. Known as WezRat, this remote access trojan (RAT) and information stealer has been active since at least September 2023, and is primarily being deployed in cyberattacks against Israeli organizations. The malware, which is equipped with a wide range of malicious capabilities, is designed to perform reconnaissance and execute remote commands on compromised endpoints, making it a potent tool for cyber espionage.

image for illustration from : bankinfosecurity.com
The Nature of WezRat
WezRat has been classified as an advanced cyber tool with the ability to carry out numerous malicious activities. According to cybersecurity firm Check Point, the malware can execute system commands, capture screenshots, upload and download files, perform keylogging, and extract clipboard contents and cookies from browsers. One of its most notable features is that it can operate via separate modules, which are delivered from a command-and-control (C&C) server in the form of Dynamic Link Library (DLL) files. This modular design allows WezRat to evade detection and makes its core component less suspicious to security systems.
The malware is believed to be the work of Cotton Sandstorm, an Iranian hacking group known for conducting politically motivated cyberattacks. The group is also recognized by other aliases, such as Emennet Pasargad and Aria Sepehr Ayandehsazan (ASA).
How WezRat is Deployed
The malware was first identified by both U.S. and Israeli cybersecurity agencies, which described it as a tool designed for information gathering and remote command execution. WezRat is distributed through trojanized versions of legitimate software, specifically Google Chrome installers. These malicious installers, when executed, not only install the legitimate browser but also drop a secondary executable file named Updater.exe (internally labeled as bd.exe), which establishes communication with a C&C server and waits for further instructions.
Check Point’s investigation revealed that WezRat has been primarily distributed to Israeli organizations through phishing emails. The emails, sent on October 21, 2024, appeared to come from the Israeli National Cyber Directorate (INCD) and urged recipients to install an urgent security update for Google Chrome. However, instead of a legitimate update, the installation package carried the malicious payload.

Depiction of the killchain of the RAT WezRat.
Malware Capabilities and Evolution
Once executed, WezRat connects to a specific C&C server, such as connect.il-cert[.]net, and uses a “password” parameter to ensure proper functionality. If the password is incorrect, the malware may malfunction or crash. The malware’s capabilities have evolved over time. Early versions of WezRat had hardcoded C&C server addresses and offered basic RAT functionalities. However, the newer variants are more sophisticated and feature additional tools for data exfiltration and monitoring, such as screenshot capture, keylogging, and cookie theft from Chromium-based browsers.
The backend infrastructure of WezRat suggests that its development involves at least two distinct teams. The continuous updates and improvements point to a long-term commitment by the attackers to maintain a highly flexible and evasive tool for cyber espionage.
Conclusion
WezRat is a clear indication of the growing threat posed by state-sponsored actors, specifically Iranian hacking groups, targeting geopolitical adversaries and organizations of strategic interest. The malware’s versatile capabilities make it a potent tool for cyber surveillance and intelligence gathering. Organizations, especially those in Israel or involved in sensitive geopolitical matters, should take immediate action to protect against WezRat and other advanced cyber threats by maintaining up-to-date security measures, staying vigilant against phishing attacks, and employing robust endpoint protections.
jaideàmafaçon : to voyc cyuk !
메타데이터
- post_id
- ec7d79c061b6
- slug
- wezrat-malware-iranian-hackers-target-israeli-organizations-with-advanced-cyber-espionage-tool-ec7d79c061b6
- url
- https://medium.com/@banzance/wezrat-malware-iranian-hackers-target-israeli-organizations-with-advanced-cyber-espionage-tool-ec7d79c061b6
- canonical_url
- https://medium.com/@banzance/wezrat-malware-iranian-hackers-target-israeli-organizations-with-advanced-cyber-espionage-tool-ec7d79c061b6
- author_url
- https://medium.com/@banzance
- status
- ok
- fetched_at
- 2026-07-21 22:11:56