{"id":7541,"date":"2018-07-26T10:02:00","date_gmt":"2018-07-26T10:02:00","guid":{"rendered":"http:\/\/e762fe57-56ed-46b7-ab04-57f9c22143e2"},"modified":"2018-07-26T10:02:00","modified_gmt":"2018-07-26T10:02:00","slug":"hacking-campaign-combines-attacks-to-target-government-finance-and-energy","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/","title":{"rendered":"Hacking campaign combines attacks to target government, finance and energy"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2018\/07\/25\/0656dc56-c40a-4259-8b6f-8d1141187229\/thumbnail\/770x578\/7488bbfb1183283375e38a1c4f625927\/leaves.jpg\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>A newly uncovered cyber espionage <span data-shortcode=\"annotation\" data-id=\"operation\" data-type=\"CNET_FAM_LINE\" data-canon=\"Operation\" data-text=\"operation\" data-score=\"18\">operation<\/span> is combining the use of known exploits and attacks with custom-built malware in a campaign which has targeted hundreds of organisations, particularly those in government, finance and energy.<\/p>\n<p>Discovered by <a href=\"https:\/\/www.symantec.com\/blogs\/threat-intelligence\/leafminer-espionage-middle-east\">researchers at Symantec<\/a>, the new <span data-shortcode=\"annotation\" data-id=\"zt-group\" data-type=\"CNET_FAM_LINE\" data-canon=\"ZT Group\" data-text=\"group\" data-score=\"46\">group<\/span> is called Leafminer and has been operating out of Iran since at least early 2017.<\/p>\n<p>The malware and custom <span data-shortcode=\"annotation\" data-id=\"774e23d0-33a6-4a5f-a942-f884cca8bf69\" data-type=\"CNET_CAT_TOPIC\" data-canon=\"Tools\" data-text=\"tools\" data-score=\"148\">tools<\/span> used by Leafminer have been detected across 44 systems in the Middle East &#8211; 28 in Saudi Arabia, <span data-shortcode=\"annotation\" data-id=\"15012872\" data-type=\"CNET_CMP_MFR\" data-canon=\"Eight\" data-text=\"eight\" data-score=\"2\">eight<\/span> in Lebanon, <span data-shortcode=\"annotation\" data-id=\"15010597\" data-type=\"CNET_CMP_MFR\" data-canon=\"Three\" data-text=\"three\" data-score=\"4\">three<\/span> in Israel, <span data-shortcode=\"annotation\" data-id=\"15012392\" data-type=\"CNET_CMP_MFR\" data-canon=\"The One\" data-text=\"one\" data-score=\"4\">one<\/span> in Kuwait and four in unknown <span data-shortcode=\"annotation\" data-id=\"3973d1aa-d8bf-4657-b8b6-684629212b1c\" data-type=\"CNET_FAM_SERIES\" data-canon=\"Tile Locator\" data-text=\"locations\" data-score=\"10\">locations<\/span> &#8211; but the investigation into the campaign found a list of 809 targets.<\/p>\n<p>Activity by the attackers suggests the goal of the campaign is to steal data, including emails, credentials, files and information on database servers operated by compromised targets.<\/p>\n<p>Leafminer uses three main techniques for compromising <span data-shortcode=\"annotation\" data-id=\"target\" data-type=\"CNET_FAM_LINE\" data-canon=\"Target\" data-text=\"target\" data-score=\"26\">target<\/span> networks &#8211; watering hole attacks, vulnerabilities in network <span data-shortcode=\"annotation\" data-id=\"laser-tek-services\" data-type=\"CNET_FAM_LINE\" data-canon=\"Laser Tek Services\" data-text=\"services\" data-score=\"10\">services<\/span> and brute-force dictionary attacks which attempt to crack passwords. Researchers note <a href=\"https:\/\/www.zdnet.com\/article\/what-is-phishing-how-to-protect-yourself-from-scam-emails-and-more\/\">that phishing emails might also be used<\/a>, but direct evidence for this hasn&#8217;t yet been seen.<\/p>\n<p>It&#8217;s the watering hole attacks and the discovery of compromised websites which initially led <span data-shortcode=\"annotation\" data-id=\"275688\" data-type=\"CNET_CMP_MFR\" data-canon=\"Symantec\" data-text=\"Symantec\" data-score=\"223\">Symantec<\/span> on the <span data-shortcode=\"annotation\" data-id=\"svs-soundpath\" data-type=\"CNET_FAM_LINE\" data-canon=\"SVS SoundPath\" data-text=\"path\" data-score=\"10\">path<\/span> to detect Leafminer. The watering hole attacks saw obfuscated JavaScript code left on targeted websites as a means of abusing SMB protocols to retrieve passwords.<\/p>\n<p>Compromised targets included a Lebanese government site, a Saudia Arabian healthcare site and an Azerbaijan university. Researchers note that the same technique was <a href=\"https:\/\/www.zdnet.com\/article\/hack-attack-on-energy-companies-raises-sabotage-fears\/\">deployed by the DragonFly hacking group last year<\/a> &#8211; but rather than being a related <span data-shortcode=\"annotation\" data-id=\"logitech-attack\" data-type=\"CNET_FAM_LINE\" data-canon=\"Logitech Attack\" data-text=\"attack\" data-score=\"82\">attack<\/span> group, Leafminer appears to <span data-shortcode=\"annotation\" data-id=\"272918\" data-type=\"CNET_CMP_MFR\" data-canon=\"Be Incorporated\" data-text=\"be\" data-score=\"6\">be<\/span> mimicking the attack.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p><strong><strong><span data-shortcode=\"annotation\" data-id=\"acdsee\" data-type=\"CNET_FAM_LINE\" data-canon=\"ACDSee\" data-text=\"See\" data-score=\"52\">See<\/span> also:<\/strong><\/strong> <strong><a href=\"https:\/\/www.techrepublic.com\/article\/can-russian-hackers-be-stopped-heres-why-it-might-take-20-years\/\">Can Russian hackers be stopped? Here&#8217;s why it might take 20 years<\/a><\/strong> <strong>[TechRepublic]<\/strong><\/p>\n<p>This isn&#8217;t the only tactic which Leafminer has picked up of successful campaigns by <span data-shortcode=\"annotation\" data-id=\"e643661a-2647-4cc8-9755-c05a6157632a\" data-type=\"CNET_CAT_TOPIC\" data-canon=\"Other\" data-text=\"other\" data-score=\"18\">other<\/span> criminal groups. Leafminer uses <a href=\"https:\/\/www.zdnet.com\/article\/wannacrypt-ransomware-microsoft-issues-patch-for-windows-xp-and-other-old-systems\/\">EternalBlue<\/a> &#8211; the <a href=\"https:\/\/www.zdnet.com\/article\/shadow-brokers-latest-file-drop-shows-nsa-targeted-windows-pcs-banks\/\">leaked NSA vulnerability<\/a> which powered <a href=\"https:\/\/www.zdnet.com\/article\/wannacry-ransomware-crisis-one-year-on-are-we-ready-for-the-next-global-cyber-attack\/\">WannaCry ransomware<\/a> &#8211; to move <span data-shortcode=\"annotation\" data-id=\"l-com-within-series\" data-type=\"CNET_FAM_LINE\" data-canon=\"L-com Within Series\" data-text=\"within\" data-score=\"2\">within<\/span> targeted networks.<\/p>\n<p>The attackers also attempt to <span data-shortcode=\"annotation\" data-id=\"socketscan\" data-type=\"CNET_FAM_LINE\" data-canon=\"SocketScan\" data-text=\"scan\" data-score=\"2\">scan<\/span> for <a href=\"https:\/\/www.zdnet.com\/article\/how-to-recover-from-heartbleed\/\">Heartbleed<\/a>, an OpenSSL vulnerability which could allow attackers to see <span data-shortcode=\"annotation\" data-id=\"toshiba-encrypted\" data-type=\"CNET_FAM_LINE\" data-canon=\"Toshiba Encrypted\" data-text=\"encrypted\" data-score=\"2\">encrypted<\/span> data. Heartbleed came to light in 2014, <a href=\"https:\/\/www.zdnet.com\/article\/heartbleed-bug-still-affects-thousands-of-sites\/\">but thousands of sites still remain vulnerable<\/a>.<\/p>\n<p>Another known technique is lifted in order to help exfiltrate data. <a href=\"https:\/\/www.zdnet.com\/article\/dancing-around-security-products-to-execute-code-on-windows\/\">Known as Doppelg\u00e4nging<\/a>, the process was revealed late last year and circumvents security tools by using process hollowing to make the malicious processes look benign.<\/p>\n<p>The use of all the above leads Symantec to state that Leafminer actively <span data-shortcode=\"annotation\" data-id=\"1c16fdfd-c387-11e2-8208-0291187b029a\" data-type=\"CNET_CAT_TOPIC\" data-canon=\"Monitors\" data-text=\"monitors\" data-score=\"10\">monitors<\/span> developers and <span data-shortcode=\"annotation\" data-id=\"6245895\" data-type=\"CNET_CMP_MFR\" data-canon=\"Publications International, LTD.\" data-text=\"publications\" data-score=\"10\">publications<\/span> of offensive techniques for ideas.<\/p>\n<p>But the campaign isn&#8217;t purely based on re-purposed attacks deployed by others, as Leafminer has also deployed two strains of custom malware during their campaigns &#8211; <a href=\"https:\/\/www.symantec.com\/security-center\/writeup\/2018-052111-1609-99\">Imecab<\/a> and <a href=\"https:\/\/www.symantec.com\/security-center\/writeup\/2018-052111-1102-99\">Sorgu<\/a>.<\/p>\n<p>Imecab is <span data-shortcode=\"annotation\" data-id=\"eeab0e88-7ca8-4a74-8c32-a809b9239a0d\" data-type=\"CNET_FAM_SERIES\" data-canon=\"Incase Designs Series\" data-text=\"designed\" data-score=\"2\">designed<\/span> to set up persisent <span data-shortcode=\"annotation\" data-id=\"apple-remote-access\" data-type=\"CNET_FAM_LINE\" data-canon=\"Apple Remote Access\" data-text=\"remote access\" data-score=\"4\">remote access<\/span> to a target machine with a hard-coded password and is installed as a Windows service in order to ensure it remains available to the attacker.<\/p>\n<p>Sorgu is used in a similar <span data-shortcode=\"annotation\" data-id=\"yezz-fashion\" data-type=\"CNET_FAM_LINE\" data-canon=\"YEZZ Fashion\" data-text=\"fashion\" data-score=\"10\">fashion<\/span>, providing remote access to the <span data-shortcode=\"annotation\" data-id=\"infected\" data-type=\"CNET_FAM_LINE\" data-canon=\"Infected\" data-text=\"infected\" data-score=\"2\">infected<\/span> machine and is also installed as a service in the Windows system via a shell <span data-shortcode=\"annotation\" data-id=\"276213\" data-type=\"CNET_CMP_MFR\" data-canon=\"Command Communications\" data-text=\"command\" data-score=\"10\">command<\/span> script.<\/p>\n<p>But while the Leafminer group appears keen to <span data-shortcode=\"annotation\" data-id=\"learn\" data-type=\"CNET_FAM_LINE\" data-canon=\"Learn\" data-text=\"learn\" data-score=\"2\">learn<\/span> from other successful espionage campaigns, one thing it has failed at is operational security: researchers uncovered a staging server used by the attackers to be publicly accessible, exposing the group&#8217;s entire <span data-shortcode=\"annotation\" data-id=\"arsenal\" data-type=\"CNET_FAM_LINE\" data-canon=\"Arsenal\" data-text=\"arsenal\" data-score=\"10\">arsenal<\/span> of tools, indicating inexperience by the attackers.<\/p>\n<p>This public information also led to a list of over 800 potential targets in government, finance and energy across the Middle East. The list is written in the Iranian Farsi language, leading researchers to conclude that the group is based in Iran &#8211; although there&#8217;s currently no evidence of it being <a href=\"https:\/\/www.zdnet.com\/article\/iran-poised-to-launch-cyberattacks-after-nuclear-deal-collapses\/\" target=\"_blank\">a state-backed campaign<\/a>.<\/p>\n<p>No matter who is behind the campaign, it&#8217;s likely that the group will continue to develop offensive techniques &#8211; and they could even widen the scope of malicious attacks.<\/p>\n<p>&#8220;It&#8217;s possible the group would keep adopting and <span data-shortcode=\"annotation\" data-id=\"a351bced-a587-4927-9473-691f1dacb0ba\" data-type=\"CNET_FAM_SERIES\" data-canon=\"Avaya - adapter Series\" data-text=\"adapting\" data-score=\"2\">adapting<\/span> both new publicly available hacking tools and techniques, as well as proof-of-concept exploits for new and old vulnerabilities,&#8221; Armin Buescher, Threat Researcher at Symantec told ZDNet.<\/p>\n<p>&#8220;In terms of targeting, the attackers might continue going after targets in the Middle East, perhaps even expanding to countries outside of the region.&#8221;<\/p>\n<p><strong>READ MORE ON CYBER CRIME<\/strong><\/p>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attack group operating out of Iran copies techniques used in successful, high-profile attacks &#8211; but forget to cover their tracks, leaving their tactics exposed.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":7542,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-7541","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hacking campaign combines attacks to target government, finance and energy 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hacking campaign combines attacks to target government, finance and energy 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-07-26T10:02:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hacking campaign combines attacks to target government, finance and energy\",\"datePublished\":\"2018-07-26T10:02:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/\"},\"wordCount\":712,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/\",\"name\":\"Hacking campaign combines attacks to target government, finance and energy 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg\",\"datePublished\":\"2018-07-26T10:02:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hacking campaign combines attacks to target government, finance and energy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hacking campaign combines attacks to target government, finance and energy 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/","og_locale":"en_US","og_type":"article","og_title":"Hacking campaign combines attacks to target government, finance and energy 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-07-26T10:02:00+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hacking campaign combines attacks to target government, finance and energy","datePublished":"2018-07-26T10:02:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/"},"wordCount":712,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/","url":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/","name":"Hacking campaign combines attacks to target government, finance and energy 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg","datePublished":"2018-07-26T10:02:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy.jpg","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hacking-campaign-combines-attacks-to-target-government-finance-and-energy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Hacking campaign combines attacks to target government, finance and energy"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/7541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=7541"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/7541\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/7542"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=7541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=7541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=7541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}