No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Sustained ‘Red Deer’ Phishing Attacks Impersonate Israel Post, Drop RATs

June 4, 2023
in Protection
0
Sustained 'Red Deer' Phishing Attacks Impersonate Israel Post, Drop RATs



Israeli engineering and telecommunications companies have been targeted with a sustained phishing message campaign that is convincingly impersonating Israel’s postal service.

Research by Perception Point found the phishing email typically appears to be a missed delivery note containing an HTML link. When clicked, it downloads and opens an .html file attachment on the user’s browser. This html file then opens an ISO image file that contains an obfuscated Visual Basic script, which ultimately downloads a modified version of the AsyncRAT malware.

Named Operation Red Deer, due to the fact that the logo for the Israel Postal Company (aka “Israel Post”) is a red deer — this technique was initially spotted being used in a campaign in April 2022, but last month a similar campaign was spotted wherein the malware version and SSL certificate that was used were the same.

Sustained Phishing Campaign

Several other campaigns in the activity cluster were also detected, including one last June and another last October, where Igal Lytzki, incident response analyst at Perception Point, says the volume of phishing emails was significantly higher than on other days.

Perception Point called the campaign “a sustained and clandestine operation” which targeted numerous organizations from diverse industries, but all based in Israel.

Lytzki says that “hundreds of emails related to this particular campaign” were detected and quarantined before being delivered, and that they’ve been directed at employees in varying positions and at different levels of seniority, not solely executive and leadership positions.

He also added that the level of care to make the lures look genuine is notable, including the addition of elements such as the logo, correlation of colors, and additional information about the post office’s opening hours. “This is a surprising tactic that reveals the depth of sophistication and investment put into this attack,” he notes.

Who Is to Blame?

The attacks were attributed to the Aggah threat group, due to the choice of malware, order-related phishing messages, and use of Losh Crypter obfuscated PowerShell scripts. Lytzki says there is no clear evidence of any state-sponsorship or national identity for Aggah, but there is a striking similarity between Aggah’s tactics, techniques, and procedures (TTPs) and another threat group known as Gorgon Group, a state-sponsored group under the Pakistani government .

He adds, “Aggah has targeted a variety of countries for espionage, information gathering, and financial gain. I believe that the evidence suggests that this hacking group is for hire, contracting with other governments to launch malicious campaigns on their behalf.”

Also, in the past, Aggah has conducted attacks which were primarily focused on organizations within Middle Eastern countries. The Gorgon Group, meanwhile, does not just focus on financial fraud and cybercrime, but also conducts attacks against government organizations and has been linked to attacks against Russia, Spain, the United Kingdom, and the United States.

Editorial Team

Editorial Team

Related Posts

The TP-Link Tapo SolarCam C402 Kit Is 30% Off Right Now
Protection

The TP-Link Tapo SolarCam C402 Kit Is 30% Off Right Now

February 25, 2026
What Is a Strength Training 'Deload,' and When Do You Need One?
Protection

What Is a Strength Training ‘Deload,’ and When Do You Need One?

February 25, 2026
Apple Is Finally Making Texting Between iPhone and Android Secure
Protection

Apple Is Finally Making Texting Between iPhone and Android Secure

February 25, 2026
The Award-Winning XREAL One Pro AR Smart Glasses Are at a Great Price Right Now
Protection

The Award-Winning XREAL One Pro AR Smart Glasses Are at a Great Price Right Now

February 25, 2026
Now Discord Is Saying It's Delaying Global Age Verification
Protection

Now Discord Is Saying It’s Delaying Global Age Verification

February 24, 2026
Samsung's February Security Patch Is Now Available on These Devices
Protection

Samsung’s February Security Patch Is Now Available on These Devices

February 24, 2026
Load More
Next Post
Ministerial Panel Starts Talks After 2-Hour Delay

Ministerial Panel Starts Talks After 2-Hour Delay

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • Here’s the Oura Ring Data You Can Access Without a Subscription

    0 shares
    Share 0 Tweet 0
  • I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0
  • Top companies hiring August 2023

    0 shares
    Share 0 Tweet 0

Latest News

Trump makes little mention of China in the longest State of the Union speech

Trump makes little mention of China in the longest State of the Union speech

February 25, 2026
0

U.S. President Donald Trump shakes hands with members of Congress as he departs following his State of the Union address...

Bitcoin Adoption Is Booming, Even If Its Price Isn’t: River Report

Bitcoin Adoption Is Booming, Even If Its Price Isn’t: River Report

February 25, 2026
0

River Financial has reported that Bitcoin Adoption metrics hit record highs in 2025, with institutional and corporate entities accumulating 829,000...

AI disruption prompts Australia’s WiseTech to cut a third of global workforce

AI disruption prompts Australia’s WiseTech to cut a third of global workforce

February 25, 2026
0

AI disruption prompts Australia’s WiseTech to cut a third of global workforce

American tequila sales are collapsing. Diageo is cutting its dividend in half.

American tequila sales are collapsing. Diageo is cutting its dividend in half.

February 25, 2026
0

Diageo on Wednesday said it was cutting its dividend in half as it reduced its sales outlook, citing American consumer...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.