Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Actor240524

Also known as: quishing, APT33, Curious Serpens, Elfin, Refined Kitten, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

Actor240524 first surfaced in early July 2024, mounting highly targeted attacks against diplomatic personnel in Azerbaijan and Israel. Their initial access vector relied on spear‑phishing emails containing either macro‑enabled Word documents or QR code images that direct users to Microsoft Sway web pages hosting the malicious abcloader payload. Upon execution, abcloader installs a lightweight backdoor component named abcsync that downloads additional modules from temporary domains such as TEMP.* and demo-cloud.space, establishing command‑and‑control over standard HTTP/HTTPS channels. The backdoor’s operational profile mirrors typical APT frameworks: it persists via registry run‑keys, scheduled tasks, and autostart directories; it steals credentials by dumping LSASS memory or reading Windows credential stores; it archives collected files locally with RAR or makecab before exfiltrating them over HTTPS or cloud storage services such as OneDrive. To evade detection the group employs several obfuscation techniques, including Base64/RC5‑encrypted payloads, DLL side‑loading, and event‑log tampering. While no destructive or ransomware activity has yet been observed, actor240524’s sophisticated use of DGA-like temporary domains, cloud‑based exfiltration, and modular downloader architecture suggests a mature threat actor capable of adapting its toolkit in response to defensive measures.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Education
Healthcare
Manufacturing
Non profit
Critical infrastructure
Energy
Media
Aviation
Pharmaceutical
Hospitality
Retail
Aerospace
Information technology
Mining
Think tank
Gaming
Transportation
Chemical
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

US
CN
IL
AZ
RU
IR
PK
VN
JP
GB
AU
SA
IN
TW
AE
UA
DE
SG
KR
PL
BY
KP
TR
MX
ES
CA
RO
FR
NG
IT
LB
KZ

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Actor240524 is a sophisticated espionage actor that emerged in July 2024, targeting diplomatic officials in Azerbaijan and Israel through meticulously crafted spear‑phishing campaigns. The group delivers malicious Microsoft Word documents or QR codes linking to Microsoft Sway pages that host a custom loader, which then deploys a backdoor that exfiltrates data over standard web protocols while maintaining persistence via registry run‑keys and scheduled tasks.

Goals & Targeting

Actor240524 appears driven by political espionage objectives rather than financial gain. The group focuses on high‑profile diplomatic entities within Azerbaijan, Israel, and broadly across the global North‑South divide, seeking to collect sensitive governmental or bilateral negotiation data that can influence foreign policy or intelligence assessments. Their targeting profile aligns with state‑level actors looking to undermine diplomatic relationships and gather strategic leverage from key international players.

Enhanced Description

Key Capabilities

  • Spear‑phishing with macro‑enabled Office documents
  • QR‑code delivery via Microsoft Sway web pages
  • Custom loader abcloader and backdoor abcsync
  • Dynamic domain generation (TEMP.*) for C2 routing
  • HTTP/HTTPS and cloud storage exfiltration (OneDrive)
  • Local data staging and archiving with RAR/makecab
  • Persistence via registry run‑keys, scheduled tasks, autostart scripts
  • Credential theft through LSASS memory dumps and credential store extraction
  • Obfuscated payloads using Base64/RC5 encryption
  • DLL side‑loading and event-logging tampering for defense evasion

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Collection
Command and Control
Exfiltration

ATT&CK Techniques

T1566.001
T1204.002
T1059.001
T1059.003
T1547
T1064
T1071
T1005
T1110
T1119
T1140
T1560
T1567
T1586

Software / Tooling

abcloader
abcsync
Microsoft Sway
PowerShell
rundll32.exe
cmd.exe
schtasks.exe

Campaigns & Victims

The only documented campaign dates back to July 2024 and was narrowly focused on Azerbaijan–Israel diplomatic contacts. The operation employed a blend of social engineering, cross‑platform delivery via QR codes, and cloud‑based exfiltration, indicating a well‑resourced threat actor comfortable with both traditional and emerging techniques. While there is no evidence yet of repeated attacks outside the initial window or diversification into other geopolitical targets, the modular nature of abcsync suggests potential for rapid expansion into additional sectors if operational goals shift.

IOC Patterns

  • Spear-phishing attachments containing macro‑enabled Office documents
  • QR code links directing victims to Microsoft Sway pages hosting custom loaders
  • Use of temporary domains such as TEMP.* and demo-cloud.space for C2 communication
  • Exfiltration via HTTPS or cloud storage services (OneDrive)
  • Persistence through run-key injections, scheduled tasks, and autostart scripts

Recommended Actions

  • Enforce strict email filtering to block macro-enabled attachments from unknown senders
  • Deploy user training that highlights QR‑code phishing risks and safe browsing hygiene
  • Enable endpoint visibility on registry run‑keys, scheduled tasks, and autostart directories to detect persistence mechanisms
  • Block outbound HTTPS traffic to suspicious or newly registered temporary domains (e.g., TEMP.*)
  • Monitored cloud‑storage activity for unusual upload patterns from internal systems
  • Implement file‑integrity monitoring to detect unauthorized RAR/makecab archives on endpoints
  • Apply least privilege and multi‑factor authentication across all diplomatic accounts

Suggested Tags

APT
espionage
state-sponsored
political target
diplomatic operations
spear-phishing
macro-based malware
cloud exfiltration
QR-code phishing
regional focus: Azerbaijan, Israel

Confidence Assessment

The narrative is based on a single July 2024 campaign that cites spear‑phishing with macro‑enabled Office documents and QR code delivery via Microsoft Sway. While the described TTPs are well documented in the source material, no additional campaigns or attribution evidence have been corroborated beyond this single incident. Key gaps include lack of first/last seen dates for actor activity, limited public information on broader operational scope, and no confirmed links to known country‑level threat groups.

ATT&CK Techniques

Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: T1134
  3. www.cybereason.com — Cited by web research for: NOOPLDR
  4. blog.talosintelligence.com — Cited by web research for: PureCrypter

Intel Summary

48

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

APT
Critical Infrastructure
Phishing
Data Exfiltration
Government Targeting
Espionage
Diplomatic Sector
State-sponsored
espionage
state-sponsored
political target
diplomatic operations
spear-phishing
macro-based malware
cloud exfiltration
QR-code phishing
regional focus: Azerbaijan, Israel

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.