DuneQuixote campaign targets Middle Eastern entities with “CR4T” malware
ID: 6cb3bd73-3efc-5242-ac04-725f0eb1d7d3
STIX ID: report--6cb3bd73-3efc-5242-ac04-725f0eb1d7d3
Feed Name: Securelist by Kaspersky
Kaspersky researchers identify and analyze the "DuneQuixote" campaign targeting government entities in the Middle East that uses malicious droppers (including a tampered Total Commander installer) to deploy memory-only backdoors named CR4T (C/C++ and Golang variants). The report documents sophisticated evasion and anti-analysis techniques, C2-decryption tied to runtime filename, named-pipe command shells, file upload/download, COM-based persistence and Telegram-based C2 in the Go variant, lists domains/IPs and numerous sample hashes, and notes observed victim telemetry and hosting infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
