logo

'Crafty Camel' APT Targets Aviation, OT With Polygot Files

ID: c1306ce8-b676-51e0-a858-56feb252f713

STIX ID: report--c1306ce8-b676-51e0-a858-56feb252f713

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-05

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Executive Summary: Proofpoint observed a highly targeted espionage campaign (Crafty Camel) leveraging business email compromise to deliver novel polyglot files that unpack a Golang backdoor called Sosano to a small set of aviation, satellite communications, and critical transportation organizations in the UAE; Proofpoint links the TTPs to Iranian-aligned threat clusters and highlights the adversary's emphasis on stealth and analysis-evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.