Also known as: APT34, Earth Preta, Stately Taurus, Storm-0978, Tropical Scorpius, UNC2596, APT28, Fancy Bear, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Evasive Panda, NIOBIUM, RENEGADE JACKAL, Scimitar, Arid Viper
UnsolicitedBooker, often conflated with multiple aliases including APT34, OilRig, and Stately Taurus, is a state‑aligned espionage group whose operations span at least a decade. The actor’s methodology centers on spear‑phishing campaigns that exploit webmail services and LinkedIn social engineering to capture login credentials, enabling the user to gain initial access into target networks. Once inside, the group deploys sophisticated backdoor loaders – notably MarsSnake and LuciDoor – which provide a full remote command–and–control channel. These backdoors support arbitrary code execution, file staging, credential dumping, and lateral movement via scheduled tasks or autostart mechanisms, allowing UnsolicitedBooker to maintain long‑term persistence in government and critical infrastructure environments. Operationally, the group exhibits a high degree of persistence, re‑engaging the same victims over multiple years – most visibly with an unnamed Saudi organization. The actor’s campaigns, such as DNSpionage (2018–19), HardPass (2019–20), and recent Middle East strikes in 2023, demonstrate proficiency at leveraging custom load‑or delivery modules, exploiting webmail servers, and maintaining covert footholds. From a defensive perspective, UnsolicitedBooker’s toolbox – comprising backdoors, credential harvesters, and remote execution frameworks – represents a significant security risk to organizations handling high‑value political or industrial data in the target regions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UnsolicitedBooker is a China‑aligned APT group that also goes by names such as APT34, OilRig, and Stately Taurus. The actor has repeatedly targeted government, defense, telecom, energy, NGO, and high‑profile industry entities across the Middle East, North Africa, Eastern Europe, and Asia by spear‑phishing with LinkedIn and stolen webmail credentials, deploying persistent backdoors such as MarsSnake and LuciDoor to remotely control victim systems.
Goals & Targeting
UnsolicitedBooker’s strategic objective is state‑level espionage, aiming to obtain actionable intelligence on governmental policy, defense capabilities, corporate secrets, and diplomatic communications. The group focuses on sectors that support critical national infrastructure: telecommunications, energy, nuclear, maritime, aviation, and financial services. Its use of webmail credential theft indicates a preference for low‑profile infiltration paths that can bypass perimeter defenses while providing broad access to internal workflows.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Known campaigns attributed to UnsolicitedBooker illustrate a consistent focus on Saudi, Middle Eastern, and select European targets. DNSpionage (2018‑19) targeted Lebanese and UAE government entities using DNS exfiltration. HardPass (2019‑20), delivered via LinkedIn spearphishing, struck energy industry participants in the Gulf region. In early 2020, a telecom operator and the Vatican were compromised by a separate backdoor delivery chain. The actor continued to hit Middle Eastern organizations into 2023, using backdoors such as MarsSnake to establish long‑term persistence. Across these campaigns, UnsolicitedBooker adapts its tactics – shifting from DNS exfiltration to phishing and custom load‑or delivery – while maintaining a stealthy presence for extended periods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the compiled profile is moderate. The numerous aliases and overlapping attribution evidence suggest a single state‑aligned actor, but the lack of precise first/last sighting data and incomplete exploitation details introduce uncertainty. Further verification of tool signatures and campaign overlap would strengthen attribution certainty.
No campaigns linked yet.
No observed data linked yet.
27
Techniques
51
Tools
0
Campaigns
6
IOCs
0
Observed Data
10
Tactics