Cyber Threat Alert: Iranian Group Suspected in Watering Hole Attack Targeting Israeli Shipping and Financial Industries

Cybersecurity researchers have recently uncovered a watering hole attack that targeted at least eight different websites associated with shipping, logistics, and financial services companies in Israel. The attack, which is believed to have been carried out by an Iranian threat actor tracked as Tortoiseshell, has raised concerns about the continued targeting of Israel by Iranian state-sponsored groups.

A watering hole attack is a type of cyber attack that involves infecting a website that is frequently visited by a targeted group of users or individuals within a specific industry. The goal is to distribute malware to these users when they visit the infected site, essentially poisoning the watering hole that they rely upon for information and resources.

Suspected Iranian threat actor: Tortoiseshell

ClearSky, the Israel-based cybersecurity firm that discovered the recent watering hole attack, has attributed it with low confidence to an Iranian threat actor known as Tortoiseshell. Tortoiseshell has been active since at least July 2018 and has been linked to multiple cyberattacks in the Middle East region. These attacks have included the targeting of IT providers in Saudi Arabia as well as the creation of fake hiring websites for US military veterans.

The goal of these fake websites was to trick veterans into downloading remote access trojans (RATs), which would allow the attackers to gain control of their systems. While these websites were shut down quickly, they demonstrated Tortoiseshell’s ability to create convincing and effective social engineering tactics to achieve its objectives.

Strategic Website Compromises

The attack method used in the recent watering hole attack on Israeli websites is known as strategic website compromise. This attack method involves infecting a commonly-visited website within a specific targeted industry sector with malware.

The idea is that visitors to these sites are more likely to have valuable information that the attackers can exploit. By compromising the website, the attackers can then distribute malware to a large number of visitors, effectively creating a foothold into their targets’ networks.

Malicious JavaScript injected into infected websites

In the case of the recent watering hole attack on Israeli shipping and financial services websites, the attackers injected malicious JavaScript into the sites. This code was designed to collect information about the visitors’ systems and send it back to a remote server for analysis.

The JavaScript code also attempted to determine the user’s language preference, a sign that the attackers were looking to target specific individuals or groups who spoke a particular language. To control the infected sites and continue to collect information, the attackers used a command-and-control (C2) domain named jquery-stack[.]online.

Israel continues to be the target of Iranian hackers

The recent watering hole attack on Israeli shipping and financial services websites is just one of many that have targeted Israeli organizations over the past few years. Iranian state-sponsored hacker groups have been particularly aggressive in targeting Israel, with multiple high-profile attacks aimed at Israeli shipping ports and infrastructure in recent years.

The continued targeting of Israel by Iranian hackers is a concerning trend, indicating that they see Israel as a particularly valuable target for their cyber operations. With the latest watering hole attack, it is clear that Israeli organizations and government agencies need to remain vigilant against these threats and take proactive measures to protect their assets and systems.

In conclusion, the recent watering hole attack on Israeli shipping and financial services websites is a potent reminder of the ongoing threat posed by state-sponsored hacker groups. While the attribution of the attack to Tortoiseshell is uncertain at this stage, the use of strategic website compromises and malicious JavaScript code indicates the involvement of a sophisticated attacker with significant resources and expertise. To protect against such threats, it is essential that organizations remain vigilant, implement security best practices, and stay up-to-date with the latest threat intelligence.

Explore more

How Agentic AI Combats the Rise of AI-Powered Hiring Fraud

The traditional sanctity of the job interview has effectively evaporated as sophisticated digital puppets now compete alongside human professionals for high-stakes corporate roles. This shift represents a fundamental realignment of the recruitment landscape, where the primary challenge is no longer merely identifying the best talent but confirming the actual existence of the person on the other side of the screen.

Can the Rooney Rule Fix Structural Failures in Hiring?

The persistent tension between traditional executive networking and formal hiring protocols often creates an invisible barrier that prevents many of the most qualified candidates from ever entering the boardroom or reaching the coaching sidelines. Professional sports and high-level executive searches operate in a high-stakes environment where decision-makers often default to known quantities to mitigate perceived risks. This reliance on familiar

How Can You Empower Your Team To Lead Without You?

Ling-yi Tsai, a distinguished HRTech expert with decades of experience in organizational change, joins us to discuss the fundamental shift from hands-on management to systemic leadership. Throughout her career, she has specialized in integrating HR analytics and recruitment technologies to help companies scale without losing their agility. In this conversation, we explore the philosophy of building self-sustaining businesses, focusing on

How Is AI Transforming Finance in the SAP ERP Era?

Navigating the Shift Toward Intelligence in Corporate Finance The rapid convergence of machine learning and enterprise resource planning has fundamentally shifted the baseline for financial performance across the global market. As organizations navigate an increasingly volatile global economy, the traditional Enterprise Resource Planning (ERP) model is undergoing a radical evolution. This transformation has moved past the experimental phase, finding its

Who Are the Leading B2B Demand Generation Agencies in the UK?

Understanding the Landscape of B2B Demand Generation The pursuit of a sustainable sales pipeline has forced UK enterprises to rethink how they engage with a fragmented and increasingly skeptical digital audience. As business-to-business marketing matures, demand generation has moved from a secondary support function to the primary engine for organizational growth. This analysis explores how top-tier agencies are currently navigating