Summary
Key Points:
- Screening Serpens, an Iranian APT group, has been observed conducting espionage campaigns targeting entities in the U.S., Israel, and the UAE, deploying six new RAT variants between February and April 2026.
- The group employs tailored social engineering tactics, including spear phishing with job requisitions and impersonation of trusted brands, to initiate infections. The use of AppDomainManager hijacking allows them to disable security mechanisms in .NET applications, enhancing their operational resilience.
- Organizations should implement robust EDR solutions fine-tuned to detect DLL sideloading and AppDomainManager hijacking techniques. Regular security training for employees on recognizing phishing attempts is also recommended.
Technical Details: The campaigns leverage AppDomainManager hijacking to manipulate .NET application initialization, allowing attackers to execute malicious payloads while bypassing traditional security measures. This technique is coupled with DLL sideloading for execution.
MITRE ATT&CK Techniques:
- T1566 - Phishing (Initial Access)
- T1203 - User Execution (Execution)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1547.001 - Boot or Logon Autostart Execution: Scheduled Task (Persistence)
- T1055.001 - Process Injection: DLL Injection (Execution)
IOCs Mentioned:
- Domains: licencemanagers.azurewebsites[.]net, NanoMatrix.azurewebsites[.]net, PremierHealthAdvisory.azurewebsites[.]net
- SHA256 Hashes: 44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250 (MiniUpdate), 8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b (Portable Platform.zip)
This summary provides actionable intelligence for analysts to enhance defenses against ongoing threats from Screening Serpens.
Join the discussion — sign up to comment, upvote, and save articles.