{"id":4248,"date":"2022-08-31T10:47:28","date_gmt":"2022-08-31T15:47:28","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4248"},"modified":"2022-08-31T10:47:28","modified_gmt":"2022-08-31T15:47:28","slug":"unc3890-cybercriminal-group-targets-israeli-organizations","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/","title":{"rendered":"UNC3890 Cybercriminal Group Targets Israeli Organizations"},"content":{"rendered":"<p>A Persian-speaking threat group called UNC3890 has been discovered that targets industries ranging from healthcare to energy, with a particular focus on the shipping sector. According to experts, the campaign uses social engineering lures transmitted via email and a watering hole hosted on a legitimate login page of an Israeli shipping company to disguise the activity.<\/p>\n<p>The hacker group has also targeted some global companies, indicating that their activity may go beyond Israel, although there is no known target outside of Israel as of yet. Experts said the group is linked to Iran or so it is believed and found some technical traces that point to an Iranian link, such as the use of Persian, including the word &#8220;joda&#8221;, which means &#8220;God&#8221;.<\/p>\n<p>The group appeared to pursue activities that would support Iranian interests and operations, including shipping groups handling sensitive components. The attacks targeting Israeli entities were similar to those of other Iranian attackers.<\/p>\n<p>While the exact method of initial entry is unknown, it is suspected to be a combination of watering holes, credential harvesting by posing as legitimate services, and fraudulent job offers for a software developer position at data analytics company LexisNexis.<\/p>\n<p>One of UNC3890&#8217;s most recent attempts to target victims involves the use of a video commercial for AI-based robot puppets, which are used as decoys to deliver SUGARDUMP.<\/p>\n<p>SUGARUSH, the second custom malware, works by connecting to an embedded C2 server to execute arbitrary CMD commands from the attacker, giving the attacker full control over the victim&#8217;s environment upon first access, so be aware of the use of this tool.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>UNC3890 an alleged group of dangerous threat activities has been in constant activity and today we will talk about this malicious group&#8230;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4249,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4248","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>UNC3890 Cybercriminal Group Targets Israeli Organizations - Truxgo Server Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"UNC3890 Cybercriminal Group Targets Israeli Organizations - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"UNC3890 an alleged group of dangerous threat activities has been in constant activity and today we will talk about this malicious group......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-08-31T15:47:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/group.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"489\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"UNC3890 Cybercriminal Group Targets Israeli Organizations\",\"datePublished\":\"2022-08-31T15:47:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/\"},\"wordCount\":272,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/group.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/\",\"name\":\"UNC3890 Cybercriminal Group Targets Israeli Organizations - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/group.jpg\",\"datePublished\":\"2022-08-31T15:47:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/group.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/group.jpg\",\"width\":800,\"height\":489,\"caption\":\"Young hacker in data security concept\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/unc3890-cybercriminal-group-targets-israeli-organizations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"UNC3890 Cybercriminal Group Targets Israeli Organizations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"UNC3890 Cybercriminal Group Targets Israeli Organizations - Truxgo Server Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/","og_locale":"es_MX","og_type":"article","og_title":"UNC3890 Cybercriminal Group Targets Israeli Organizations - Truxgo Server Blog","og_description":"UNC3890 an alleged group of dangerous threat activities has been in constant activity and today we will talk about this malicious group......","og_url":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-08-31T15:47:28+00:00","og_image":[{"width":800,"height":489,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/group.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"UNC3890 Cybercriminal Group Targets Israeli Organizations","datePublished":"2022-08-31T15:47:28+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/"},"wordCount":272,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/group.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/","url":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/","name":"UNC3890 Cybercriminal Group Targets Israeli Organizations - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/group.jpg","datePublished":"2022-08-31T15:47:28+00:00","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/group.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/group.jpg","width":800,"height":489,"caption":"Young hacker in data security concept"},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/unc3890-cybercriminal-group-targets-israeli-organizations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"UNC3890 Cybercriminal Group Targets Israeli Organizations"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4248","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4248"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4248\/revisions"}],"predecessor-version":[{"id":4250,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4248\/revisions\/4250"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4249"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4248"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4248"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}