logo

Oil and Gas Industries in Middle East Targeted

ID: 11009b8d-adc6-5b4c-88ac-8ed8eba9ada4

STIX ID: report--11009b8d-adc6-5b4c-88ac-8ed8eba9ada4

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ observed a targeted email campaign (since Jan–May 2020 with increased activity from July 2020) that uses malicious PDF attachments impersonating ADNOC-related RFQs; the PDFs host links to ZIP archives containing a packed .NET loader which unpacks multiple staged DLLs (Aphrodite, Jupiter) and ultimately injects the AZORult infostealer via process hollowing to exfiltrate data to crevisoft.net. The report includes technical analysis of packing/decryption, extensive sandbox/anti-VM checks, C2 artifacts, PHP mailer scripts, a MITRE ATT&CK mapping, and many IoCs (hashes, URLs, scheduled task names and dropped filenames) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.