Kasablanka: The Emerging North African Cyber Threat Actor
ID: aafc7dc7-4998-530e-87f7-29c114d269b0
STIX ID: report--aafc7dc7-4998-530e-87f7-29c114d269b0
Feed Name: Brandefense Blog
Kasablanka is an emerging North African cyber threat actor active since 2021 that has matured from hacktivist website defacements into a hybrid APT conducting targeted phishing, credential theft, and espionage against governments, energy, and media organizations; the report outlines its TTPs (spearphishing, watering holes, cloud token theft, persistence via RATs), observed operations from 2021–2025, use of cloud-based C2/exfiltration (Dropbox, Google Drive, Telegram), and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
