---
title: Suspected Iranian hackers target Israeli shipping and logistics companies
description: Several shipping and logistics websites in Israel were hacked to gather information about their users, according to a report by Tel Aviv-based cybersecurity company ClearSky.
image: https://channel16.dryadglobal.com/hubfs/Close-up%20dark%20keyboard%20with%20coding%20and%20programing%20concept-1.jpeg
---

###### 2 min read

# Suspected Iranian hackers target Israeli shipping and logistics companies

By: [ The Record ](https://channel16.dryadglobal.com/archive/author/the-record) on  June 6, 2023 at 8:00 AM

[Maritime Security](https://channel16.dryadglobal.com/archive/tag/maritime-security) [Cyber Security](https://channel16.dryadglobal.com/archive/tag/cyber-security) [cyber risk](https://channel16.dryadglobal.com/archive/tag/cyber-risk) [maritime cyber security](https://channel16.dryadglobal.com/archive/tag/maritime-cyber-security)

- [**](https://twitter.com/GlobalDryad)
- [**](https://www.linkedin.com/company/dryad-global/)
- [**](https://www.youtube.com/channel/UCZSIjPkeq7iDcsj4r9TF9mg?sub_confirmation=1)

![Featured Image](https://channel16.dryadglobal.com/hubfs/Close-up%20dark%20keyboard%20with%20coding%20and%20programing%20concept-1.jpeg)

Several shipping and logistics websites in Israel were hacked to gather information about their users, according to a report by Tel Aviv-based cybersecurity company ClearSky.

The company [attributes these attacks](https://www.clearskysec.com/fata-morgana/) “with a low confidence” to the Iranian nation-state hacker group Tortoiseshell, also called TA456 and Imperial Kitten. The threat actor has been active since at least July 2018.

The hacking campaign targeted at least eight Israeli websites — including shipping company SNY Cargo, logistics firm Depolog and restaurant equipment supplier SZM — with a watering hole attack. Most websites were already cleared of the malicious code as of April 18, ClearSky said.

[![What is the risk to your operations?](https://no-cache.hubspot.com/cta/default/4795492/31ed1823-b3e6-4fd8-8534-78413f1943fc.png)](https://cta-redirect.hubspot.com/cta/redirect/4795492/31ed1823-b3e6-4fd8-8534-78413f1943fc)

In a watering hole attack, hackers compromise a website that is frequently visited by a specific group of people, such as government officials, journalists, or corporate executives. Once hacked, attackers can inject harmful code into the website, which gets activated when users visit the site.

Watering hole attacks have been used by Iranian hackers since 2017, according to ClearSky researchers. Last year, for example, a suspected Iranian threat actor tracked by Mandiant as UNC3890 [used this method](https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping) to target shipping, healthcare, government, and energy companies in Israel.

In the recent attack, hackers used malicious JavaScript. The collected data includes the user's IP address, screen resolution and the URL of the previously visited webpage.. The hackers also tried to determine the user’s computer language preference to customize their attacks in the future, ClearSky said

The majority of the compromised websites were using the uPress hosting service, which was targeted in 2020 by the Iranian group Emennet Pasargad. Thousands of Israeli sites were defaced as a result.

Israel and Iran often face-off in cyberspace to the political tension between the two countries. Some of the Iranian attacks aim to steal user data or destroy systems, others are intended [to spread disinformation](https://therecord.media/iran-apt-charming-kitten-bellaciao-malware-us-europe-asia).

The covert cyberwar between the two countries [has escalated](https://www.washingtonpost.com/politics/2022/07/25/iran-israel-cyber-war/) over the past two years. Although Iranian state-sponsored actors are not as advanced as their Russian and Chinese counterparts, they are enhancing their cyber capabilities, [according to Microsoft](https://therecord.media/iran-hackers-influence-operations-cyberattacks-microsoft). For example, they rapidly exploit recently disclosed vulnerabilities to breach organizations and use tailored tools against their targets.

Tortoiseshell has previously used both custom and off-the-shelf malware to target IT providers in Saudi Arabia with a supply chain attack aimed at compromising the IT providers' customers.

In the recent attack, hackers used the domain *jquery-stack[.]online*, which was previously attributed to Tortoiseshell. This domain impersonated the legitimate JavaScript framework jQuery to deceive anyone who checks the website code.

ClearSky researchers have already seen domain names impersonating jQuery in a previous Iranian campaign from 2017 using a watering hole attack.

Source: [The Record](https://therecord.media/israel-shipping-logistics-watering-hole-cyberattacks)

###### Share article

[![Share on Facebook](https://channel16.dryadglobal.com/hs-fs/hubfs/Drayad_DMP21/Images/fb.png?width=24&name=fb.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://channel16.dryadglobal.com/hs-fs/hubfs/Drayad_DMP21/Images/linkedin.png?width=24&name=linkedin.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://channel16.dryadglobal.com/hs-fs/hubfs/Drayad_DMP21/Images/twitter.png?width=24&name=twitter.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=Suspected%20Iranian%20hackers%20target%20Israeli%20shipping%20and%20logistics%20companies) [![Share on Pinterest](https://channel16.dryadglobal.com/hs-fs/hubfs/Drayad_DMP21/Images/pinterest.png?width=24&name=pinterest.png)](http://pinterest.com/pin/create/button/?url=https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Dpinterest&media=https%3A%2F%2Ff.hubspotusercontent40.net%2Fhubfs%2F4795492%2FDrayad_DMP21%2FImages%2Fpinterest.png) [![Share on Email](https://channel16.dryadglobal.com/hs-fs/hubfs/Drayad_DMP21/Images/mail.png?width=24&name=mail.png)](mailto:?subject=Check%20out%20https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fchannel16.dryadglobal.com%2Farchive%2Fsuspected-iranian-hackers-target-israeli-shipping-and-logistics-companies%3Futm_medium%3Dsocial%26utm_source%3Demail)

#### Related Posts

### [The Iranian armada of 'ghost' ships carrying.. Iran's "ghost" armada that carry Russian oil is growing as Western sanctions on Moscow crude..](https://channel16.dryadglobal.com/archive/the-iranian-armada-of-ghost-ships-carrying-russian-oil-is-growing)

### [Iran’s navy prevents pirate attack in Gulf of Aden An Iranian warship on Saturday prevented an attack by pirates against two oil tankers that it was..](https://channel16.dryadglobal.com/archive/irans-navy-prevents-pirate-attack-in-gulf-of-aden)

### [US introduces new round of sanctions on Iranian.. Iran's state-owned oil company and the country's biggest tanker operator blacklisted by the US. A..](https://channel16.dryadglobal.com/archive/us-introduces-new-round-of-sanctions-on-iranian-oil-companies)

##### Twitter Feeds

Twitter Feeds

[Follow @GlobalDryad](https://twitter.com/GlobalDryad?ref_src=twsrc%5Etfw)

 

##### Channel 16

Channel 16

<https://channel16.dryadglobal.com/archive/cross-strait-relations-in-the-lai-era>

###### [Cross-Strait relations in the Lai era](https://channel16.dryadglobal.com/archive/cross-strait-relations-in-the-lai-era)

 On May 20, Lai Ching-te was inaugurated as Taiwan's new president, prompting significant military...

##### Know More

Know More

##### Reach Us

Reach Us

Press/media contact  
[Email Us](mailto:press@dryadglobal.com)

General Enquiries  
[Contact Us Here](https://share.hsforms.com/1nNmumgLKRy6b7zdktrR3FQ2us84)

[![DG Logo Horizontal NEW White](https://channel16.dryadglobal.com/hs-fs/hubfs/Branding/DG%20Logo%20Horizontal%20NEW%20White.png?width=280&height=100&name=DG%20Logo%20Horizontal%20NEW%20White.png "DG Logo Horizontal NEW White")](https://dryadglobal.com)

© 2024 Dryad Global. All Rights Reserved

[**](https://twitter.com/GlobalDryad)[**](https://www.linkedin.com/company/dryad-global/)[**](https://www.youtube.com/c/IMSAGlobalDryad)

**

![](https://px.ads.linkedin.com/collect/?pid=1152100&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The Record",
    "url" : "https://channel16.dryadglobal.com/archive/author/the-record"
  },
  "dateModified" : "2023-06-06T07:00:00.764Z",
  "datePublished" : "2023-06-06T07:00:00.000Z",
  "headline" : "Suspected Iranian hackers target Israeli shipping and logistics companies",
  "image" : [ "https://channel16.dryadglobal.com/hubfs/Close-up%20dark%20keyboard%20with%20coding%20and%20programing%20concept-1.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://channel16.dryadglobal.com/archive/suspected-iranian-hackers-target-israeli-shipping-and-logistics-companies",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://channel16.dryadglobal.com/hubfs/DG%20Logo%20Featured%20Image%20Green.png"
    },
    "name" : "Dryad Global Ltd"
  }
}
```