PULSE NAME
Attack on *stan: Your malware, my C2
WHITE AlienVault 2026-01-30 Modified: 2026-03-01
51
IOCs
HIGH VOLUME
A suspected state-affiliated threat actor has been targeting Kazakh and Afghan entities in a persistent campaign since at least August 2022. The attackers use a Windows-based RAT called KazakRAT, which allows for payload downloads, host data collection, and file exfiltration. The malware is delivered via .msi files and persists using the Run registry key. C2 communications are unencrypted over HTTP. The campaign also utilizes modified versions of XploitSpy Android spyware. Multiple KazakRAT variants have been observed with minor command-set changes. Victim targeting includes government and financial sector entities, particularly in Kazakhstan's Karaganda region. The operation shows low sophistication but high persistence, with similarities to APT36/Transparent Tribe activities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
KazakRAT XploitSpy
Indicators of Compromise (13 / 51 total)
All FileHash-SHA1 FileHash-MD5 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3e9a8d405f75d0ed8fc674bfaad1f87f 2026-01-30
FileHash-MD5 687442da7be02a2a72c36a9a1dbe9b97 2026-01-30
FileHash-MD5 70e6e936c54f968d92ee38806661a539 2026-01-30
FileHash-MD5 76a7822a243f338bf3c5bc5c53997c12 2026-01-30
FileHash-MD5 7aa12bf3606e1a74597be4237ce4a6e5 2026-01-30
FileHash-MD5 86d884956a0cab7f536b3b98edea0454 2026-01-30
FileHash-MD5 87343a65550b4f7a336b892cc9188e82 2026-01-30
FileHash-MD5 9b852f9a0fb735ca809f6895afc54dca 2026-01-30
FileHash-MD5 9f660ee1b0e68a140a629b4e8842da06 2026-01-30
FileHash-MD5 a3299674576e4210a0e78fb37a27c34f 2026-01-30
FileHash-MD5 c0e58474e8a8b84862b2ef50cfc7c799 2026-01-30
FileHash-MD5 db942ba4cf38912a07eacc9e01d56574 2026-01-30
FileHash-MD5 e36f27a13054f05da69761dc830b0db3 2026-01-30