Hacking of Israeli Shipping and Logistics Companies

Year

2023

Month

May

Reference number

20230508

Impact area

Shore

Incident location

Israel

Incident country

Israel

Victim country

Israel

Victim identity

At least eight Israeli websites, including shipping company SNY Cargo, logistics firm Depolog and restaurant equipment supplier SZM.

Victim Type

Shipping and Logistics Companies

Method

Hacking

Attacker country

Iran

Summary:

On May 23, 2023 the cybersecuritry company ClearSky provided their analysis on the Fata Morgana campaign. This campaign leveraged highly sophisticated cyber techniques to target Israel’s shipping and logistics sector through watering hole attacks. Instead of directly breaching individual companies, the attackers compromised trusted industry websites frequently visited by maritime professionals. By injecting obfuscated malicious JavaScript code, they ensured that unsuspecting users would unknowingly trigger malware downloads, allowing the attackers to gain a foothold in their systems. This approach not only increased the attack's success rate but also made attribution and detection significantly more challenging. Once a visitor interacted with an infected site, the malicious script performed system reconnaissance, gathering details on the victim’s operating system, browser version, and security settings. If the system was deemed a valuable target, the attackers would deploy a multi-stage malware payload, ensuring deeper infiltration. The hackers also employed evasive techniques, such as frequently rotating Command and Control (C2) servers and encrypting data transmissions to avoid triggering security alerts. Additionally, they exploited known vulnerabilities in web browsers and plugins, leveraging unpatched software flaws to bypass traditional cybersecurity defenses. ClearSky attributed these attacks “with a low confidence” to the Iranian nation-state hacker group Tortoiseshell. The combination of these tactics highlights the strategic and calculated nature of this cyber operation, suggesting a well-funded, state-sponsored effort aimed at disrupting Israel’s maritime sector.

Reference URL

https://www.clearskysec.com/wp-content/uploads/2023/05/Fata-Morgana-Israeli-Websites-Infected-by-Iranian-Group-1.8.pdf
https://therecord.media/israel-shipping-logistics-watering-hole-cyberattacks