Subscribe to our Mailing Lists (It's free!)
Thursday, May 29, 2025
SAFETY4SEA
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    Dryad Global Black Sea security

    Dryad Global: Attacks on Ukraine’s ports likely to escalate

    fire

    Third fatality confirmed after fire on oil platform off Angola

    India monsoon

    India: Mooring and anchoring during the Monsoon season

    crane operations

    American Club: Crane operations require precision and control

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    culture of respect

    Addressing crew shortage: Establish clear expectations for respectful and professional behaviour

    Book Review: Building leaders the MMMA way

    Book Review: How to avoid a climate disaster

    mental health

    MOL takes step to enhance the mental health of its crew

    Book Review: Building leaders the MMMA way

    Book Review: The Art Of War

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    MoU hydrogen

    New MoU signed to advance hydrogen transportation

    SGS completes wind propulsion trials with promising results

    SGS completes wind propulsion trials with promising results

    COSCO

    COSCO adds dual-fuel car carrier featuring solar panels to its fleet

    Isle of Man

    Isle of Man Registry adds eco-friendly tanker under its service

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    digitalization

    New dataset aligned with IMO Compendium post-FAL 49

    Crew connectivity a ‘powerful tool’ requiring strategic deployment

    Crew connectivity a ‘powerful tool’ requiring strategic deployment

    New deal sees autonomous navigation systems for two vessels

    New deal sees autonomous navigation systems for two vessels

    cyber security

    CyberOwl raises alarm on phising and malware campaign

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    India monsoon

    India: Mooring and anchoring during the Monsoon season

    hull

    Libya mandates underwater hull inspections

    Indian Ocean MoU Annual report

    Indian Ocean MoU PSC Annual Report 2024

    Malaysia

    Malaysia detains container ship for illegal anchoring

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    norway

    Veson Nautical: Norwegian fleet is the global leader in sustainability

    offshore

    Offshore leaders collaborate on inclusive immersion suit project

    tankers

    Cook Islands registry questions ejection from RISC platform

    Drewry: Multipurpose vessel market faces multiple risks

    Drewry: Multipurpose vessel market faces multiple risks

  • Columns
    Philippines crew management

    Our people are our greatest asset

    decarbonization

    Maritime GHG regulation: Navigating the path to decarbonization

    DSG: Now is a defining moment for DEI in shipping

    DSG: Now is a defining moment for DEI in shipping

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    Dryad Global Black Sea security

    Dryad Global: Attacks on Ukraine’s ports likely to escalate

    fire

    Third fatality confirmed after fire on oil platform off Angola

    India monsoon

    India: Mooring and anchoring during the Monsoon season

    crane operations

    American Club: Crane operations require precision and control

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    culture of respect

    Addressing crew shortage: Establish clear expectations for respectful and professional behaviour

    Book Review: Building leaders the MMMA way

    Book Review: How to avoid a climate disaster

    mental health

    MOL takes step to enhance the mental health of its crew

    Book Review: Building leaders the MMMA way

    Book Review: The Art Of War

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    MoU hydrogen

    New MoU signed to advance hydrogen transportation

    SGS completes wind propulsion trials with promising results

    SGS completes wind propulsion trials with promising results

    COSCO

    COSCO adds dual-fuel car carrier featuring solar panels to its fleet

    Isle of Man

    Isle of Man Registry adds eco-friendly tanker under its service

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    digitalization

    New dataset aligned with IMO Compendium post-FAL 49

    Crew connectivity a ‘powerful tool’ requiring strategic deployment

    Crew connectivity a ‘powerful tool’ requiring strategic deployment

    New deal sees autonomous navigation systems for two vessels

    New deal sees autonomous navigation systems for two vessels

    cyber security

    CyberOwl raises alarm on phising and malware campaign

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    India monsoon

    India: Mooring and anchoring during the Monsoon season

    hull

    Libya mandates underwater hull inspections

    Indian Ocean MoU Annual report

    Indian Ocean MoU PSC Annual Report 2024

    Malaysia

    Malaysia detains container ship for illegal anchoring

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    norway

    Veson Nautical: Norwegian fleet is the global leader in sustainability

    offshore

    Offshore leaders collaborate on inclusive immersion suit project

    tankers

    Cook Islands registry questions ejection from RISC platform

    Drewry: Multipurpose vessel market faces multiple risks

    Drewry: Multipurpose vessel market faces multiple risks

  • Columns
    Philippines crew management

    Our people are our greatest asset

    decarbonization

    Maritime GHG regulation: Navigating the path to decarbonization

    DSG: Now is a defining moment for DEI in shipping

    DSG: Now is a defining moment for DEI in shipping

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
SAFETY4SEA

CyberOwl raises alarm on phising and malware campaign

by The Editorial Team
May 23, 2025
in Cyber Security
cyber security

Credit: Shutterstock

FacebookTwitterEmailLinkedin

CyberOwl has completed an investigation into a developing cyber campaign that’s impersonating players in Iranian oil and gas trade and targeting vessel captains directly.

As stated, CyberOwl has observed a phishing and malware campaign that has targeting organisations involved with trading Iranian oil and gas but which has also spread to others in the trading ecosystem including maritime operators.

The attacker set up a new domain vaproum[.]biz which was registered on 23 January 2025 and updated on 4 March 2025. This was used to send and receive emails.

RelatedNews

Survitec urges for preparation on 2026 fire protection regulations

GCMD: Significant fraction of biofuels are mislabeled

From open source research it was identified that the vaproum[.]biz domain was used to send two phishing messages impersonating SGS (a Swiss based engineering company with operations in Iran) to Sepehr Energy Jahan Nemaye Pars Co. (an Iranian organisation trading oil and gas with links to the military) on 11 March 2025. The first message has an attached password protected rar file and the second has a gz file.

Targeting a vessel

CyberOwl observed a further instance of the campaign which was sent to the email address of a vessel captain on 17 April 2025. This email was impersonating F. Taghipour a commercial manager at Smart Exports LLC which is another Iranian organisation involved in oil and gas trading. The email was simple but used a number of specific terms which would have made it seem more legitimate to the vessel captain who received it.

CyberOwl raises alarm on phising and malware campaign
Credit: CyberOwl

The email had an attached zip file containing a javascript file which contained a multi-stage downloader. After the recipient opens the attachment the malware execution begins.

Malware analysis

The attached javascript file downloads and executes content from agout12.lovestoblog.com. LovesToBlog is a free hosting site which hides details of who operates the subdomains. CyberOwl detected the attempt to launch script interpreters from an email and took action to stop the attack and protect the client. The remaining malware analysis was conducted in a lab. The next stage downloads a jpg hosted on archive.org.

The jpg contains a hidden payload which decodes to executable code. This part of the attack overlaps with a small number of other campaigns also reported from March to May 2025 but with apparently different motivations. CyberOwl’s assumption is that the attacks are all using a shared malware-as-a-service platform but are ultimately conducted by different attackers.

There are also similarities with reported attacks from 2024 that named this jpg technique as “SteganoAmor” due to the use of steganography. The executable code from the jpg is loaded directly into memory to avoid detection. The code supports persistence through scheduled tasks and arbitrary command and control functions. The remote connection is to aguout12.lovestoblog.com. The final delivered malware in this case appears to be a variant of “Agent Tesla”.

This currently appears to be a little-known campaign that is impersonating and targeting organisations involved with Iranian oil and gas. Posts on X (formerly Twitter) suggest that one of the organisations has been recently breached by an Anonymous affiliate with the intention of exposing breaches of US sanctions on Iran. The most plausible theory is therefore that the incidents reported here are part of that Anonymous campaign.

However, the vessel where the attack was detected has no links to Iranian trading and thus the true motive may be different. At least one other campaign that used the jpg hosted on archive.org is reported to have a financially motivated objective. CyberOwl has also identified impersonation of a UAE based oil & gas entity and a Chinese shipping related email lure that could indicate a wider targeting of the sector but not linked to sanctions.

Recommendations

In addition to the usual defences for phishing threats – email scanning, crew training and 24×7 monitoring – this case raises two specific issues:

  • The importance of considering the reputational impacts of a cyber-attack that reveals confidential information – particularly in light of a fast-changing sanctions environment.
  • Ensuring you have a good understanding of your business’s operations when doing a risk assessment to understand what confidential information you are protecting.

According to Marlink’s global maritime cyber threat report, during the second half of 2024, (H2) there had been an evolution in cyber threats, as malicious actors have adopted increasingly efficient, structured, and business-like approaches to cybercrime. Cybercriminals have streamlined their tactics, enhanced their operational efficiency and have adopted emerging technologies to expand their attack capabilities.

CyberOwl raises alarm on phising and malware campaignCyberOwl raises alarm on phising and malware campaign
CyberOwl raises alarm on phising and malware campaignCyberOwl raises alarm on phising and malware campaign
Tags: cyber securityloss prevention
Previous Post

Xeneta: How the tariffs truce impacts transpacific shipping

Next Post

Baltic Exchange: Maritime market highlights 19-23 May

Related News

Cyberattacks
Cyber Security

Marlink: Stronger policy and user awareness against cyber threats

May 21, 2025
cyber security
Cyber Security

USCG cyber security report finds improving landscape

May 21, 2025
Key trends in seafarer recruitment and retention
Loss Prevention

Britannia: Preparing the crew for emergencies and claims

May 16, 2025
vietnam
Loss Prevention

Gard: Minimizing dry cargo shortage claims in Vietnam

May 12, 2025
fsmc spongy moth
Loss Prevention

West P&I Club: 5 tips to comply with FSMC inspections

May 12, 2025
Watch: Lower injury rates in waterway freight transportation compared to rail or truck
Loss Prevention

Japan P&I Club: Key safety tips for dangerous tasks onboard

May 9, 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Explore more

No Result
View All Result
MARITIME EVENTS

Explore

  • Safety
  • SEAFiT
  • Green
  • Smart
  • Risk
  • Others
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

Useful Links

  • About
  • Disclaimer
  • Editorial Policies
  • Advertising
  • Content Marketing
  • Contact

© 2025 SAFETY4SEA

No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA

Manage your privacy
We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}
No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA