UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors
ID: 69cd2d84-7b76-5cf5-bc3a-72ea6f2379b7
STIX ID: report--69cd2d84-7b76-5cf5-bc3a-72ea6f2379b7
Feed Name: The Hacker News
Threat Score
The report describes China‑aligned APT "UnsolicitedBooker" shifting to target telecom providers in Kyrgyzstan and Tajikistan using phishing (malicious Word macros and LNK-based shortcuts) to deploy C++ loaders and backdoors (LuciDoor and MarsSnake) for reconnaissance and data exfiltration; it also documents related imitation campaigns (PseudoSticky) and other phishing attacks (Cloud Atlas) that exploit CVE-2018-0802 and deploy RATs like DarkTrack and Remcos.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
