DuneQuixote campaign targets Middle Eastern entities with “CR4T” malware


In February 2024, Kaspersky researchers discovered a new malware campaign targeting government entities in the Middle East.

They dubbed it “DuneQuixote”; and their investigation uncovered over 30 DuneQuixote dropper samples actively employed in the campaign. These droppers, which exist in two versions – regular droppers and tampered installer files for a legitimate tool named “Total Commander”, carried malicious code to download an additional payload in the form of a backdoor Kaspersky call “CR4T”. While the researchers identified only two CR4T implants at the time of discovery, they strongly suspect the existence of others, which may be completely different malware.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • Suspected Chinese cyber spies target unpatched SonicWall devices

    March 9, 2023

    Suspected Chinese cyber criminals have zeroed in on unpatched SonicWall gateways and are infecting the devices with credential-stealing malware that persists through firmware upgrades, according to Mandiant. The spyware targets the SonicWall Secure Mobile Access (SMA) 100 Series – a gateway device that provides VPN access to remote users. Read more… Source: The Register  

  • Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting

    March 1, 2023

    Iron Tiger is an advanced persistent threat (APT) group that has been focused primarily on cyberespionage for more than a decade. In 2022, we noticed that they updated SysUpdate, one of their custom malware families, to include new features and add malware infection support for the Linux platform. We found the oldest sample of this updated ...

  • Suspected espionage in Palestine highlights spread of hacking skills

    February 16, 2022

    A wave of recent espionage activity from suspected Palestinian hackers is the latest evidence that wealthy spy agencies no longer are the sole operators of malware that covertly vacuums up victims’ data. A shadowy group has targeted governments in the Middle East, a state-affiliated airline and foreign policy think tanks as part of a “highly targeted” ...