logo

Sponsor with batch-filed whiskers: Ballistic Bobcat’s scan and strike backdoor

ID: 033dbd95-68e3-5565-a8ec-ac227e2cb3f1

STIX ID: report--033dbd95-68e3-5565-a8ec-ac227e2cb3f1

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2023-09-11

Date Updated: 2026-05-01

...
...

ESET researchers uncovered a Ballistic Bobcat (APT35) campaign that exploited internet-facing Microsoft Exchange servers (CVE-2021-26855) to deploy a novel backdoor named Sponsor across at least 34 victims in Israel, Brazil, and the UAE; the report includes a full technical breakdown of Sponsor’s configuration, command-and-control protocol, persistence via Windows services, associated open-source tools, file and network IoCs, and MITRE ATT&CK mappings to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.