DuneQuixote campaign targets Middle Eastern entities with “CR4T” malware


In February 2024, Kaspersky researchers discovered a new malware campaign targeting government entities in the Middle East.

They dubbed it “DuneQuixote”; and their investigation uncovered over 30 DuneQuixote dropper samples actively employed in the campaign. These droppers, which exist in two versions – regular droppers and tampered installer files for a legitimate tool named “Total Commander”, carried malicious code to download an additional payload in the form of a backdoor Kaspersky call “CR4T”. While the researchers identified only two CR4T implants at the time of discovery, they strongly suspect the existence of others, which may be completely different malware.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • ToddyCat: Keep calm and check logs

    October 12, 2023

    ToddyCat is an advanced APT actor that Kaspersky researchers described in a previous publication last year. The group started its activities in December 2020 and has been responsible for multiple sets of attacks against high-profile entities in Europe and Asia. Kaspersky first publication was focused on their main tools, Ninja Trojan and Samurai Backdoor, and ...

  • Stayin’ Alive – targeted attacks against telecoms and government ministries in Asia

    October 11, 2023

    In the last few months, Check Point Research has been tracking “Stayin’ Alive”, an ongoing campaign that has been active since at least 2021. The campaign operates in Asia, primarily targeting the Telecom industry, as well as government organizations. The “Stayin’ Alive” campaign consists of mostly downloaders and loaders, some of which are used as ...

  • Assessed Cyber Structure and Alignments of North Korea in 2023

    October 10, 2023

    Historically Mandiant has made assessments on the Democratic People’s Republic of Korea’s (DPRK) cyber program based on Mandiant responses to intrusions, defector accounts, and OSINT reporting, in conjunction with government disclosures of DPRK units and motivation information. These assessments were generalizations and as new activity, such as cryptocurrency-focused units, emerged it blended the efforts from DPRK ...

  • Grayling: Previously unseen threat actor targets multiple organizations in Taiwan

    October 10, 2023

    A previously unknown advanced persistent threat (APT) group used custom malware and multiple publicly available tools to target a number of organizations in the manufacturing, IT, and biomedical sectors in Taiwan. A government agency located in the Pacific Islands, as well as organizations in Vietnam and the U.S., also appear to have been hit as ...

  • Hacktivist attacks erupt in Middle East following Hamas assault on Israel

    October 9, 2023

    Groups range from known collectives to new outfits eager to raise their profile Hacktivism efforts have proliferated rapidly in the Middle East following the official announcement of a war between Palestine and Israel.… The escalation was spurred by a deadly attack on a music festival by Hamas, along with abductions and killings across scores of Israeli ...

  • Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Org

    September 28, 2023

    The Budworm advanced persistent threat (APT) group continues to actively develop its toolset. Most recently, the Threat Hunter Team in Symantec, part of Broadcom, discovered Budworm using an updated version of one of its key tools to target a Middle Eastern telecommunications organization and an Asian government. Both attacks occurred in August 2023. Budworm (aka LuckyMouse, ...