logo

When Espionage Moves Next Door: UnsolicitedBooker's Pivot to Central Asian Telecom Networks

ID: 8ee358c9-e0cc-5c1b-a1ff-855ed75ae03a

STIX ID: report--8ee358c9-e0cc-5c1b-a1ff-855ed75ae03a

Feed Name: NoHackie

Threat Score
85/100

Date Published: 2026-03-01

Date Updated: 2026-04-19

...
...

UnsolicitedBooker, a China-aligned APT, conducted targeted spear-phishing campaigns from 2023–2026—initially focusing on a Saudi international organization using the MarsSnake backdoor, then pivoting to Kyrgyz and Tajik telecom providers using a new LuciDoor backdoor and loader rotation. The group favors macro-enabled Office documents, encrypted C2 channels, and compromises legitimate routers (notably with an identifiable PolarSSL/Mbed TLS fingerprint) to mask infrastructure; these actions underscore the intelligence value of telecom networks and highlight persistent risk to Central Asian telecommunications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.