{"id":10638,"date":"2022-02-01T17:32:04","date_gmt":"2022-02-01T16:32:04","guid":{"rendered":"https:\/\/www.show.it\/iranian-hackers-using-new-powershell-backdoor-linked-to-memento-ransomware\/"},"modified":"2022-02-01T17:32:04","modified_gmt":"2022-02-01T16:32:04","slug":"iranian-hackers-using-new-powershell-backdoor-linked-to-memento-ransomware","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/iranian-hackers-using-new-powershell-backdoor-linked-to-memento-ransomware\/","title":{"rendered":"Iranian Hackers Using New PowerShell Backdoor Linked to Memento Ransomware"},"content":{"rendered":"<p><span><span><strong>Attacks from the Iranian Phosphorus APT (aka Charming Kitten, APT35) are well documented. Now a new set of tools incorporated into the group&#8217;s arsenal, and a connection with the Memento ransomware, have been discovered.<\/strong><\/span><\/span><\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/iranian-hackers-using-new-powershell-backdoor-linked-memento-ransomware\" target=\"_blank\" rel=\"noopener\">read more<\/a><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=yIl2AUoC8zA\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:-BTjWOF_DHI\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=_QTwKt0OkSg:z9Y-xNeaC_c:-BTjWOF_DHI\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:dnMXMwOfBR0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=dnMXMwOfBR0\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=_QTwKt0OkSg:z9Y-xNeaC_c:V_sGLiPBpWU\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:qj6IDK7rITs\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=qj6IDK7rITs\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:gIN9vFwOqvQ\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=_QTwKt0OkSg:z9Y-xNeaC_c:gIN9vFwOqvQ\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:TzevzKxY174\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=TzevzKxY174\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=_QTwKt0OkSg:z9Y-xNeaC_c:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=_QTwKt0OkSg:z9Y-xNeaC_c:F7zBnMyn0Lo\" border=\"0\"><\/a>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attacks from the Iranian Phosphorus APT (aka Charming Kitten, APT35) are well documented. Now a new set of tools incorporated into the group&#8217;s arsenal, and a connection with the Memento ransomware, have been discovered. read more<\/p>\n","protected":false},"author":2,"featured_media":10639,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[21,11],"tags":[],"class_list":["post-10638","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-news-industry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/10638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=10638"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/10638\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media\/10639"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=10638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=10638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=10638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}