UnsolicitedBooker is a China-aligned APT group targeting governmental entities across Asia, Africa, and the Middle East with flight ticket-themed spear-phishing.
Analyst brief
UnsolicitedBooker is a China-aligned APT group targeting governmental organizations primarily across Asia, Africa, and the Middle East. The group relies on spear-phishing emails with flight ticket decoys to deliver the MarsSnake backdoor, enabling extensive control over compromised systems. MarsSnake allows for arbitrary command execution and file access, indicating a strong focus on persistent, long-term intelligence collection. Defenders should prioritize detecting spear-phishing lures involving flight tickets and monitor endpoints for unauthorized command execution indicative of MarsSnake C2 activity.
UnsolicitedBooker
unknown
UnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi Arabia, employing a backdoor called MarsSnake. The group utilizes spear-phishing emails, often featuring flight tickets as decoys, to infiltrate governmental organizations across Asia, Africa, and the Middle East. Their operations have included multiple intrusion attempts over several years, demonstrating a sustained interest in their target. MarsSnake provides significant control over infected machines, allowing for arbitrary command execution and file access.