MalKamak is an Iranian cyber espionage group targeting global aerospace and telecommunications sectors.
Analyst brief
MalKamak is an Iranian threat actor active since at least 2018, conducting highly targeted cyber espionage. They primarily target global aerospace and telecommunications companies. Their main TTPs involve using a sophisticated RAT called ShellClient to evade antivirus tools and leveraging cloud services like Dropbox for C2 communications. Defenders should focus on monitoring anomalous network traffic to Dropbox and endpoint behaviors associated with the ShellClient trojan.
MalKamak
unknown
MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.