logo

DuneQuixote campaign targets Middle Eastern entities with “CR4T” malware

ID: 6cb3bd73-3efc-5242-ac04-725f0eb1d7d3

STIX ID: report--6cb3bd73-3efc-5242-ac04-725f0eb1d7d3

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2024-04-18

Date Updated: 2026-04-29

Author: GReAT

...
...

Kaspersky researchers identify and analyze the "DuneQuixote" campaign targeting government entities in the Middle East that uses malicious droppers (including a tampered Total Commander installer) to deploy memory-only backdoors named CR4T (C/C++ and Golang variants). The report documents sophisticated evasion and anti-analysis techniques, C2-decryption tied to runtime filename, named-pipe command shells, file upload/download, COM-based persistence and Telegram-based C2 in the Go variant, lists domains/IPs and numerous sample hashes, and notes observed victim telemetry and hosting infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.