A University website in Iran stood out for thoroughly vetting its current and potential students and staff. The Universitys web site served repackaged content from the Browser Exploitation Framework (BeEF) with embedded JavaScript content maintaining the potential to hook visitors web browsers. The embedded BeEF content appears not to be fully configured, and only partially implemented. This sort of sites visited data gathering via other techniques, like screengrabbing and keylogging, were observed in past APT incidents like the Madi campaigns.”]
Source: https://securelist.com/freezer-paper-around-free-meat/74503/

