Metador is a threat actor known for targeting telecoms and universities in the Middle East and Africa with custom in-memory malware platforms.
Analyst brief
Metador is a threat actor targeting telecommunications, ISPs, and universities primarily in the Middle East and Africa. The actor deploys custom malware platforms like metaMain and Mafalda directly into memory to bypass native security solutions. Their key TTPs include privilege escalation via WMI event subscriptions, C2 over Web Protocols and Non-Application Layer Protocols, and stealth using encrypted files and file deletion. Defenders should focus on monitoring anomalous memory operations, unusual WMI subscriptions, and suspicious web-based C2 traffic.
Metador
unknown
Metador primarily targets telecommunications, internet service providers, and universities in several countries in the Middle East and Africa. Metador’s attack chains are designed to bypass native security solutions while deploying malware platforms directly into memory. SentinelLabs researchers discovered variants of two long-standing Windows malware platforms, and indications of an additional Linux implant.
Monitor for suspicious activities related to Windows Management Instrumentation Event Subscription and implement controls against privilege escalation.