Also known as: quishing, APT33, Curious Serpens, Elfin, Refined Kitten, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations
Actor240524 first surfaced in early July 2024, mounting highly targeted attacks against diplomatic personnel in Azerbaijan and Israel. Their initial access vector relied on spear‑phishing emails containing either macro‑enabled Word documents or QR code images that direct users to Microsoft Sway web pages hosting the malicious abcloader payload. Upon execution, abcloader installs a lightweight backdoor component named abcsync that downloads additional modules from temporary domains such as TEMP.* and demo-cloud.space, establishing command‑and‑control over standard HTTP/HTTPS channels. The backdoor’s operational profile mirrors typical APT frameworks: it persists via registry run‑keys, scheduled tasks, and autostart directories; it steals credentials by dumping LSASS memory or reading Windows credential stores; it archives collected files locally with RAR or makecab before exfiltrating them over HTTPS or cloud storage services such as OneDrive. To evade detection the group employs several obfuscation techniques, including Base64/RC5‑encrypted payloads, DLL side‑loading, and event‑log tampering. While no destructive or ransomware activity has yet been observed, actor240524’s sophisticated use of DGA-like temporary domains, cloud‑based exfiltration, and modular downloader architecture suggests a mature threat actor capable of adapting its toolkit in response to defensive measures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Actor240524 is a sophisticated espionage actor that emerged in July 2024, targeting diplomatic officials in Azerbaijan and Israel through meticulously crafted spear‑phishing campaigns. The group delivers malicious Microsoft Word documents or QR codes linking to Microsoft Sway pages that host a custom loader, which then deploys a backdoor that exfiltrates data over standard web protocols while maintaining persistence via registry run‑keys and scheduled tasks.
Goals & Targeting
Actor240524 appears driven by political espionage objectives rather than financial gain. The group focuses on high‑profile diplomatic entities within Azerbaijan, Israel, and broadly across the global North‑South divide, seeking to collect sensitive governmental or bilateral negotiation data that can influence foreign policy or intelligence assessments. Their targeting profile aligns with state‑level actors looking to undermine diplomatic relationships and gather strategic leverage from key international players.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The only documented campaign dates back to July 2024 and was narrowly focused on Azerbaijan–Israel diplomatic contacts. The operation employed a blend of social engineering, cross‑platform delivery via QR codes, and cloud‑based exfiltration, indicating a well‑resourced threat actor comfortable with both traditional and emerging techniques. While there is no evidence yet of repeated attacks outside the initial window or diversification into other geopolitical targets, the modular nature of abcsync suggests potential for rapid expansion into additional sectors if operational goals shift.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The narrative is based on a single July 2024 campaign that cites spear‑phishing with macro‑enabled Office documents and QR code delivery via Microsoft Sway. While the described TTPs are well documented in the source material, no additional campaigns or attribution evidence have been corroborated beyond this single incident. Key gaps include lack of first/last seen dates for actor activity, limited public information on broader operational scope, and no confirmed links to known country‑level threat groups.
No campaigns linked yet.
No observed data linked yet.
48
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics