Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
ID: 7df2ecdf-381f-4714-bb36-cebeddcade50
STIX ID: report--7df2ecdf-381f-4714-bb36-cebeddcade50
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-02-12
Last Modified Date: 2019-02-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
# Executive summary
Kaspersky analyzed an active Chafer APT campaign using an updated Remexi Trojan to spy on foreign diplomatic entities in Iran: Remexi collects keystrokes, screenshots, browser credentials and history, uses BITS and IIS/ASP for C2 and exfiltration, employs multiple persistence mechanisms (scheduled tasks, Run/Userinit registry entries), and the report includes compilation artifacts and extensive IoCs (file hashes, IP 108.61.189.174, mutexes, registry keys, scheduled task names).
