logo

Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

ID: 7d43ff50-ae50-5291-89ad-240eee7b79ac

STIX ID: report--7d43ff50-ae50-5291-89ad-240eee7b79ac

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A coordinated espionage campaign from Nov 2025–Feb 2026 targeted Libyan critical infrastructure (an oil refinery, a telecom, and a state institution) using politically themed spear-phishing lures and a multi-stage infection chain (VBS downloader named like "video_saif_gadafi_2026.vbs" → PowerShell dropper disguised as "image.png" → scheduled task "devil" with XML persistence) to deploy AsyncRAT, enabling sustained remote access, keystroke logging, and screen capture; investigators observed months-long persistence and recommend hardening against scripted droppers, monitoring for unusual scheduled tasks, and deploying behavior-based detection for RAT activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.