logo

Libyan Oil Refinery Among Targets in Long-running Likely Espionage Campaign

ID: 84d4214a-11d2-53b8-a9f1-bfd53b59ca57

STIX ID: report--84d4214a-11d2-53b8-a9f1-bfd53b59ca57

Feed Name: security.com

Threat Score
72/100

Date Published: 2026-03-20

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

A targeted phishing campaign from November 2025 to February 2026 used Libya-themed lure documents and VBS downloaders to deploy a PowerShell dropper and the publicly available AsyncRAT backdoor against Libyan organizations (notably an oil refinery, a telecom, and a state institution). The dropper created a scheduled task named 'devil' and fetched AsyncRAT; the report includes multiple file hashes and emphasizes the risk to energy-sector infrastructure amid regional instability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.