216.73.216.6

Call It What You Want: Threat Actor Delivers Highly Targeted Multistage Polyglot Malware

· Published 04/03/2025 22:43 · Modified 05/03/2025 16:39

Export JSON

Essential information

Published
04/03/2025 22:43
Modified
05/03/2025 16:39
Tags
2025-03-04 apt backdoor satellite sosano supply-chain targeted
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 3 others

Description

A highly email-based campaign was identified, focusing on aviation and communications organizations in the United Arab Emirates. The campaign utilized a compromised entity to send customized malicious messages, leading to the discovery of a new named . This malware employed various obfuscation techniques, including polyglot files, indicating a sophisticated adversary. The infection chain involved multiple stages, using LNK files, HTA scripts, and XOR encoding. The , written in Golang, contains limited functionality but is heavily obfuscated. The threat actor, tracked as UNK_CraftyCamel, shows possible connections to Iranian-aligned adversaries but is considered a separate entity. This campaign highlights the use of trusted relationships to deliver customized, obfuscated malware to selective targets.

External references