ALFA Wordpress attack
This is a remote access threat launched at Wordpress installs.
The following was observed when I was monitoring server logs:
It looks like a "fishing expedition" looking for files related to the Alfa Team
APT33
APT33 seem to be an Iranian Cyber-Security group that I have seen making probes on this website. The probes apparently are looking for vulnerabilites in Wordpress installations. Seeing as I don't use Wordpress, and I have stated why I have problems with Wordpress, there is little for me or vistors to this website to be concerned with.
The ALFA attack is attempt to compromise a Wordpress built website so that subversive posts can be made by hostile agents.
The ALFA teams process
A snippet from my server log can be seen at the top of this page.
alfacgiapi perl.alfa
The probe for alfacgiapi/perl.alfa seems to indicate that there was an expectation that this file existed on my server.
What Trendmicro say:
As I have been saying for a long time, CMS systems are bad news when it comes to attracting interest from the Chinese, Russians and even the Iranian's. Wordpress is particularly a good target. Not only is it a hackers target it is a great way of those so inclined to post comments on legitamet blogs that can spread propaganda.
What Mandiant say:
When discussing suspected Middle Eastern hacker groups with destructive capabilities, many automatically think of the suspected Iranian group that previously used SHAMOON – aka Disttrack – to target organizations in the Persian Gulf. However, over the past few years, we have been tracking a separate, less widely known suspected Iranian group with potential destructive capabilities, whom we call APT33. Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.