logo

Libyan Refinery Targeted in Prolonged Spy Campaign With AsyncRAT

ID: 658a30fd-4c92-5177-a26e-7b9ab5ddd2b2

STIX ID: report--658a30fd-4c92-5177-a26e-7b9ab5ddd2b2

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A sustained espionage campaign targeting Libyan critical infrastructure between November 2025 and February 2026 used spear‑phishing lures and VBS/PowerShell multi‑stage droppers to deliver the AsyncRAT backdoor, achieving persistent access to an oil company, a telecommunications provider, and a state institution; thematic lures, scheduled task persistence named "devil," and VirusTotal uploads provide IOCs, and while attribution is inconclusive the targeting and persistence suggest possible state‑aligned motives with implications for energy security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.