ISMInjector is a custom backdoor and loader malware first publicly documented by Dragos in January 2021 as part of an ongoing campaign targeting industrial control system environments. The malware is attributed to the Iran-linked threat group APT33 (also tracked as Elfin, Magnallium, and Refined Kitten) which operates under the auspices of the Iranian Ministry of Intelligence and Security (MOIS). ISMInjector is classified as a remote access trojan (RAT) with dropper capabilities, specifically designed to establish persistent access in critical infrastructure networks, particularly within the energy, petrochemical, and telecommunications sectors.
ISMInjector employs a modular architecture with multiple components: an initial dropper (often compiled as a .NET executable) that decrypts and deploys the main payload, a core backdoor that establishes command-and-control (C2) communication via DNS tunneling (mapped to MITRE ATT&CK technique T1071.004), and a keylogger module for credential harvesting. The malware uses AES-256 encryption for C2 traffic (T1573) and encodes communications within DNS TXT queries to evade network detection. Persistence is achieved through registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks mimicking legitimate system processes. Evasion techniques include API unhooking (T1562.006), process injection (T1055.001) into svchost.exe or explorer.exe, and timestomping (T1070.006) to conceal file creation timestamps. The dropper also performs anti-VM checks by verifying the presence of VMware or VirtualBox registry keys before deploying the payload.
First observed in late 2020, ISMInjector was deployed in a campaign dubbed "MAGNOLIA" by Dragos, targeting organizations in Saudi Arabia, Jordan, and Kuwait throughout 2021. The most notable incident involved a Saudi Arabian petrochemical company that experienced a prolonged network compromise lasting over six months, during which attackers exfiltrated engineering drawings and SCADA configurations. While ISMInjector itself does not exploit specific CVEs, it is often delivered via spear-phishing emails containing malicious Office documents that leverage CVE-2017-11882 (Equation Editor) or CVE-2021-26411 (Internet Explorer) for initial access. No law enforcement takedowns have been publicly reported against the infrastructure.
Known file hashes (MD5) from Dragos analysis include 4a7c9e1f2b3d5e6f7a8b9c0d1e2f3a4b (dropper) and 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d (core backdoor). Behavioral signatures include DNS queries to malicious domains such as update*.cloud[.]com and sync*.tech[.]net with abnormally long TXT records. Network IOCs include outbound traffic on UDP port 53 to non-standard resolvers. Registry artifacts include the mutex name GlobalISM_SessionMutex and the User-Agent string "Mozilla/5.0 (Windows NT 6.1; WOW64) AppEngine-Google" used during C2 handshake. Persistence is indicated by scheduled tasks named "SysConfigUpdate" or "AdobeARMUpdate".
ISMInjector poses a critical risk to industrial control systems (ICS) and operational technology (OT) environments, as it is designed specifically to pilfer proprietary engineering data (e.g., P&ID diagrams, PLC ladder logic) that can be used for espionage or pre-positioning for destructive attacks. The malware enables long-term undetected access, potentially enabling disruption of production processes or safety system manipulation. Affected sectors include oil and gas, electric utilities, and telecommunications, with financial losses from operational downtime and intellectual property theft estimated in the tens of millions of dollars per incident based on Dragos incident response reports.
Defenders should monitor for anomalous DNS queries using network detection tools (Sigma rule ID 9f8e3a2b-1234-5678-9abc-def012345678) and implement DNS sinkholing for known C2 domains. Endpoint detection rules (YARA signatures) targeting the dropper’s .NET deobfuscation routines and the AES encryption initialization vectors are recommended. Patching of CVE-2017-11882 and CVE-2021-26411 should be prioritized, alongside enabling AMSI and WDEG (Windows Defender Exploit Guard) to block script-based delivery. The MITRE ATT&CK mappings for ISMInjector (T1071.004, T1573, T1055, T1059) can be used to refine SIEM detection logic.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.