Hackers Target Middle East Governments with Evasive "CR4T" Backdoor
ID: 58059336-bc77-5393-8eb4-b5a9133db05c
STIX ID: report--58059336-bc77-5393-8eb4-b5a9133db05c
Feed Name: The Hacker News
Kaspersky uncovered a targeted cyber-espionage campaign named DuneQuixote that has been delivering a backdoor called CR4T to Middle Eastern government entities via droppers (including a trojanized Total Commander installer). The campaign uses novel C2-decryption (MD5 derived from filename plus embedded Spanish-poem snippets), strong anti-analysis checks, memory-only implants, and a Golang variant that supports COM object hijacking for persistence and Telegram-based C2, indicating a capable, actively evolving threat actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
