logo

UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors

ID: 69cd2d84-7b76-5cf5-bc3a-72ea6f2379b7

STIX ID: report--69cd2d84-7b76-5cf5-bc3a-72ea6f2379b7

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes China‑aligned APT "UnsolicitedBooker" shifting to target telecom providers in Kyrgyzstan and Tajikistan using phishing (malicious Word macros and LNK-based shortcuts) to deploy C++ loaders and backdoors (LuciDoor and MarsSnake) for reconnaissance and data exfiltration; it also documents related imitation campaigns (PseudoSticky) and other phishing attacks (Cloud Atlas) that exploit CVE-2018-0802 and deploy RATs like DarkTrack and Remcos.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.