14/12/2025

https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html

Karkoff 2020: a new APT34 campaign involves Lebanon Government

" is still active, and this campaign against the Lebanon government demonstrates it. The new version of the Karkoff malware is the demonstration that the Iran-linked APT34 cyberespionage group continues to improve its arsenal. The sample involved in this campaign implements new reconnaissance capabilities, it implements a covert and effective C2 communication channel through the use of the Microsoft Exchange Protocol."