logo

Hackers Target Middle East Governments with Evasive "CR4T" Backdoor

ID: 58059336-bc77-5393-8eb4-b5a9133db05c

STIX ID: report--58059336-bc77-5393-8eb4-b5a9133db05c

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-04-19

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Kaspersky uncovered a targeted cyber-espionage campaign named DuneQuixote that has been delivering a backdoor called CR4T to Middle Eastern government entities via droppers (including a trojanized Total Commander installer). The campaign uses novel C2-decryption (MD5 derived from filename plus embedded Spanish-poem snippets), strong anti-analysis checks, memory-only implants, and a Golang variant that supports COM object hijacking for persistence and Telegram-based C2, indicating a capable, actively evolving threat actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.