Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Metador

Description

Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication companies, internet service providers, and universities in the Middle East and Africa. Security researchers named the group Metador based on the "I am meta" string in one of the group's malware samples and the expectation of Spanish-language responses from C2 servers.(Citation: SentinelLabs Metador Sept 2022)

AI Analysis

· 1 week ago

Executive Summary

Metador is a suspected cyber espionage group targeting telecommunication companies, internet service providers, and universities in the Middle East and Africa since September 2022. The group uses sophisticated malware and tools to conduct its activities, posing significant risks to critical infrastructure and sensitive data.

Goals & Targeting

Metador likely aims to gather sensitive information for espionage purposes by targeting sectors with strategic significance in specific regions. Their focus on telecom and ISPs suggests an interest in communications data, while targeting universities may indicate a desire for intellectual property or research data.

Enhanced Description

Metador, first identified in September 2022, is a cyber espionage group targeting sectors with sensitive information. Named after the 'I am meta' string found in its malware, the group's operations suggest a focus on intelligence gathering. It has primarily targeted Middle East and African regions, though specifics of its targets and motivations remain under investigation. The use of tools like Mafalda and metaMain indicates technical proficiency.

Key Capabilities

  • Advanced malware
  • Encrypted file usage
  • Command shell utilization

MITRE ATT&CK Tactics

Collection
Execution
Credential Access

ATT&CK Techniques

T1588.001
T1588.002
T1059.003
T1070.004
T1071.001
T1027.013
T1546.003
T1095
T1105

Software / Tooling

Mafalda
metaMain

Campaigns & Victims

Metador's campaigns appear to be limited in scope but highly targeted. They have shown sustained activity over time, with a focus on long-term data collection rather than immediate damage. Notable operations include malware deployments that leverage encrypted communication channels.

IOC Patterns

  • Malware using 'I am meta' string
  • Encrypted/encoded files
  • Command and control (C2) via non-standard protocols

Recommended Actions

  • Monitor for advanced persistent threat (APT) activities
  • Implement robust endpoint detection and response (EDR) solutions
  • Conduct regular user training on phishing and malware awareness

Suggested Tags

APT
espionage
cyber espionage
Middle East targets
telecommunications

Confidence Assessment

Medium-high confidence in Metador's existence as an APT group based on technical evidence. Limited data availability regarding exact motivations and full range of TTPs creates some uncertainties.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. SentinelLabs Metador Sept 2022 — Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.

Intel Summary

9

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT
Backdoor / C2
espionage
cyber espionage
Middle East targets
telecommunications

Details

MITRE ID
G1013
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--bfc5ddb3-4dfb-4278-8928-020e1b3feddd
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.