Libyan Refinery Targeted in Prolonged Spy Campaign With AsyncRAT
ID: 658a30fd-4c92-5177-a26e-7b9ab5ddd2b2
STIX ID: report--658a30fd-4c92-5177-a26e-7b9ab5ddd2b2
Feed Name: GBHackers
A sustained espionage campaign targeting Libyan critical infrastructure between November 2025 and February 2026 used spear‑phishing lures and VBS/PowerShell multi‑stage droppers to deliver the AsyncRAT backdoor, achieving persistent access to an oil company, a telecommunications provider, and a state institution; thematic lures, scheduled task persistence named "devil," and VirusTotal uploads provide IOCs, and while attribution is inconclusive the targeting and persistence suggest possible state‑aligned motives with implications for energy security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
