PULSE NAME
Call It What You Want: Threat Actor Delivers Highly Targeted Multistage Polyglot Malware
WHITE UNK_CraftyCamel AlienVault 2025-03-04 Modified: 2025-04-03
16
IOCs
MEDIUM VOLUME
A highly targeted email-based campaign was identified, focusing on aviation and satellite communications organizations in the United Arab Emirates. The campaign utilized a compromised entity to send customized malicious messages, leading to the discovery of a new backdoor named Sosano. This malware employed various obfuscation techniques, including polyglot files, indicating a sophisticated adversary. The infection chain involved multiple stages, using LNK files, HTA scripts, and XOR encoding. The Sosano backdoor, written in Golang, contains limited functionality but is heavily obfuscated. The threat actor, tracked as UNK_CraftyCamel, shows possible connections to Iranian-aligned adversaries but is considered a separate entity. This campaign highlights the use of trusted relationships to deliver customized, obfuscated malware to selective targets.
Indicators of Compromise (16)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 19dabeca5fe5f5f35382f8e19c0d4403 2025-03-04
FileHash-MD5 35c29b31c3564e7d7cae9901299d41dd 2025-03-04
FileHash-MD5 6bd3be2a2d5d01ffa2c061ed63ac290f 2025-03-04
FileHash-MD5 fbf3c44fdf1d635d1142ae0ec32fe887 2025-03-04
FileHash-SHA1 304a9849894df9e6b3d381f2d24bcf2ef5b497fb 2025-03-04
FileHash-SHA1 cf136da651dfb9104dcba68460ff57288b8c2ff9 2025-03-04
FileHash-SHA1 f336903e65598cdc4908ee4ac0ff106c8c7fb027 2025-03-04
FileHash-SHA1 f5e1b8a9a9ebce41fe734b82a312046b3d7d44a4 2025-03-04
FileHash-SHA256 0ad1251be48e25b7bc6f61b408e42838bf5336c1a68b0d60786b8610b82bd94c 2025-03-04
FileHash-SHA256 0c2ba2d13d1c0f3995fc5f6c59962cee2eb41eb7bdbba4f6b45cba315fd56327 2025-03-04
FileHash-SHA256 336d9501129129b917b23c60b01b56608a444b0fbe1f2fdea5d5beb4070f1f14 2025-03-04
FileHash-SHA256 394d76104dc34c9b453b5adaf06c58de8f648343659c0e0512dd6e88def04de3 2025-03-04
FileHash-SHA256 e692ff3b23bec757f967e3a612f8d26e45a87509a74f55de90833a0d04226626 2025-03-04
URL https://indicelectronics.net/or/1/OrderList.zip 2025-03-04
domain bokhoreshonline.com 2025-03-04
domain indicelectronics.net 2025-03-04