Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UnsolicitedBooker

Also known as: APT34, Earth Preta, Stately Taurus, Storm-0978, Tropical Scorpius, UNC2596, APT28, Fancy Bear, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Evasive Panda, NIOBIUM, RENEGADE JACKAL, Scimitar, Arid Viper

Description

UnsolicitedBooker, often conflated with multiple aliases including APT34, OilRig, and Stately Taurus, is a state‑aligned espionage group whose operations span at least a decade. The actor’s methodology centers on spear‑phishing campaigns that exploit webmail services and LinkedIn social engineering to capture login credentials, enabling the user to gain initial access into target networks. Once inside, the group deploys sophisticated backdoor loaders – notably MarsSnake and LuciDoor – which provide a full remote command–and–control channel. These backdoors support arbitrary code execution, file staging, credential dumping, and lateral movement via scheduled tasks or autostart mechanisms, allowing UnsolicitedBooker to maintain long‑term persistence in government and critical infrastructure environments. Operationally, the group exhibits a high degree of persistence, re‑engaging the same victims over multiple years – most visibly with an unnamed Saudi organization. The actor’s campaigns, such as DNSpionage (2018–19), HardPass (2019–20), and recent Middle East strikes in 2023, demonstrate proficiency at leveraging custom load‑or delivery modules, exploiting webmail servers, and maintaining covert footholds. From a defensive perspective, UnsolicitedBooker’s toolbox – comprising backdoors, credential harvesters, and remote execution frameworks – represents a significant security risk to organizations handling high‑value political or industrial data in the target regions.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Non profit
Education
Think tank
Energy
Media
Healthcare
Maritime
Manufacturing
Critical infrastructure
Aerospace
Pharmaceutical
Legal services
Transportation
Nuclear
Entertainment
Aviation
Chemical
Hospitality
Utilities
Information technology

Targeted Countries / Regions

RU
CN
UA
US
IL
AE
PK
IN
BY
KR
JP
VN
PL
IR
LB
TR
TW
KZ
KP
SA
IQ
DE
IT
FR
RO

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

UnsolicitedBooker is a China‑aligned APT group that also goes by names such as APT34, OilRig, and Stately Taurus. The actor has repeatedly targeted government, defense, telecom, energy, NGO, and high‑profile industry entities across the Middle East, North Africa, Eastern Europe, and Asia by spear‑phishing with LinkedIn and stolen webmail credentials, deploying persistent backdoors such as MarsSnake and LuciDoor to remotely control victim systems.

Goals & Targeting

UnsolicitedBooker’s strategic objective is state‑level espionage, aiming to obtain actionable intelligence on governmental policy, defense capabilities, corporate secrets, and diplomatic communications. The group focuses on sectors that support critical national infrastructure: telecommunications, energy, nuclear, maritime, aviation, and financial services. Its use of webmail credential theft indicates a preference for low‑profile infiltration paths that can bypass perimeter defenses while providing broad access to internal workflows.

Enhanced Description

Key Capabilities

  • Deploys persistent backdoors such as MarsSnake and LuciDoor
  • Uses spearphishing via LinkedIn to harvest webmail credentials
  • Targets government officials, think tanks, military personnel, NGOs, energy, telecom and industrial sectors
  • Develops custom loaders for shared malware delivery
  • Conducts phishing campaigns that impersonate flight tickets or legitimate services

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution

ATT&CK Techniques

T1005
T1033
T1036
T1053
T1055
T1057
T1059
T1071
T1082
T1102
T1105
T1106
T1120
T1123
T1203
T1204
T1529
T1555
T1547
T1548
T1559
T1561
T1566
T1566.001
T1566.002

Software / Tooling

LuciDoor
MarsSnake
OilRig
Lyceum
ShroudedSnooper
BladedFeline
StrongPity
InvisiMole
VERMIN
China Chopper
KONNI
Attor
Zebrocy
ShadowPad
Gelsemium
Mimikatz
Sofacy
Sednit
Turla
Winnti
Cobalt Strike
PowerShell
Explorer
Bahamut
Crisis
Custom Malware
Unknown
Custom Tools
Buhtrap
DONOT
Ghost RAT
Global
Kimsuky
XDSpy
ClickFix
Backdoors
Group Policy
Custom Backdoors
RoundCube
Trojans
Mikroceen RAT
Infostealer
ZEROLOT
MuddyWater

Campaigns & Victims

Known campaigns attributed to UnsolicitedBooker illustrate a consistent focus on Saudi, Middle Eastern, and select European targets. DNSpionage (2018‑19) targeted Lebanese and UAE government entities using DNS exfiltration. HardPass (2019‑20), delivered via LinkedIn spearphishing, struck energy industry participants in the Gulf region. In early 2020, a telecom operator and the Vatican were compromised by a separate backdoor delivery chain. The actor continued to hit Middle Eastern organizations into 2023, using backdoors such as MarsSnake to establish long‑term persistence. Across these campaigns, UnsolicitedBooker adapts its tactics – shifting from DNS exfiltration to phishing and custom load‑or delivery – while maintaining a stealthy presence for extended periods.

IOC Patterns

  • Domain
  • File
  • Email
  • Webmail credential theft
  • Spearphishing via email

Recommended Actions

  • Implement SPF/DKIM/DMARC policies to block forged email senders targeting webmail services.
  • Provide targeted phishing awareness training that focuses on LinkedIn‑based spoofing and flight‑ticket decoys.
  • Deploy EDR solutions capable of detecting persistence mechanisms such as auto‑start registry keys, scheduled tasks, and remote backdoor shells.
  • Block known C2 domains and IPs associated with MarsSnake, LuciDoor, and other UnsolicitedBooker artifacts via threat feeds.
  • Enforce network segmentation to limit lateral movement from compromised endpoints.
  • Monitor for anomalous credential usage or webmail login patterns indicative of credential theft.
  • Deploy privilege‑elevation detection controls to flag abused elevation mechanisms (T1548).
  • Employ least‑privilege and MFA enforcement on all critical infrastructure accounts.
  • Conduct regular threat hunting for custom loaders, shared malware footprints, and remote execution signatures.

Suggested Tags

UnsolicitedBooker
COPIED
APT34
OilRig
Iran-aligned
MiddleEast_Targeting
Phishing
LinkedIn_Phishing
DNSpionage
Target - Government
Target - NGO
Target - Energy Sector
Target - Telecommunications
Region - Middle East
Region - East Asia
Campaign - DNSpionage 2018-2019
Campaign - HardPass 2019–2020
Campaign - 2023 Middle East Attacks

Confidence Assessment

Confidence in the compiled profile is moderate. The numerous aliases and overlapping attribution evidence suggest a single state‑aligned actor, but the lack of precise first/last sighting data and incomplete exploitation details introduce uncertainty. Further verification of tool signatures and campaign overlap would strengthen attribution certainty.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.eset.com — Cited by web research for: APT34
  2. attack.mitre.org — Cited by web research for: T1548
  3. www.welivesecurity.com — Cited by web research for: RoundCube
  4. www.welivesecurity.com — Cited by web research for: Information Technology
  5. https://www.eset.com/us/business/services/apt-reports/?srsltid=AfmBOop7gsU1O83WQs6KIXwGdc1C5a7gWENsKFTlo1PPxvB_f1R2SSG3 — Cited by AI analysis.

Intel Summary

27

Techniques

51

Tools

0

Campaigns

6

IOCs

0

Observed Data

10

Tactics

Tags

APT
Phishing
Backdoor / C2
Government Targeting
China-aligned APT
State-sponsored espionage
Long-term campaign
Government-targeted
UnsolicitedBooker
COPIED
APT34
OilRig
Iran-aligned
MiddleEast_Targeting
LinkedIn_Phishing
DNSpionage
Target - Government
Target - NGO
Target - Energy Sector
Target - Telecommunications
Region - Middle East
Region - East Asia
Campaign - DNSpionage 2018-2019
Campaign - HardPass 2019–2020
Campaign - 2023 Middle East Attacks

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.