IR

TA455TA455

Also known as: TA455

Origin
IR
Known aliases
1

Profile

TA455 is an Iranian APT group targeting the aerospace industry through a campaign known as the “Iranian Dream Job Campaign,” utilizing deceptive job offers to lure victims. They employ spearphishing tactics with malicious ZIP files containing the executable “secur32[.]dll” and disguise their C2 communications within the traffic of reputable services like Cloudflare and GitHub. The group intentionally mimics the TTPs of the North Korean Lazarus group to mislead investigators and complicate attribution. Their multi-stage infection strategy enhances the likelihood of success while evading detection.

Aliases· 1

TA455

Compliance frameworks testing this (incoming)2

TypeTargetConfidenceTier
ComplianceControlai_act-art9100%live
ComplianceControliso27701-a.7.2.1100%live

References

  1. https://www.clearskysec.com/irdreamjob24/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA453
Actor
Group5
Actor
TA2541
Actor
APT45
Actor
TA402
Actor
TA575
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.