Also known as: SIG37
This actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation' leak. Earliest known sighting potentially dates back to as far as 2008 with a confirmed center of activity around 2010-2013. The actor name is derived from a PDB debug string fragment: 'khzer'. Victimology indicates targeting of Iran, assessed with low confidence based on VT file submission locations. Nazar employs a modular toolkit where a main dropper silently registers multiple DLLs as OLE controls in the Windows registry. Functionality includes keylogging, sound and screen grabbing, as well as traffic capture using the MicroOlap Packet Sniffer library.
Executive Summary
Nazar, also known as SIG37, is a potentially long-standing cyber threat actor identified through the ShadowBrokers' 'Lost in Translation' leak. The actor has been observed since 2008 but was most active between 2010 and 2013. Nazar employs a modular toolkit for surveillance activities including keylogging, screen and sound capture, and network traffic interception using the MicroOlap Packet Sniffer library.
Goals & Targeting
While Nazar's broader targeting strategy remains unclear, there is low-confidence intelligence suggesting an interest in victims within Iran. The actor's modular toolkit suggests a focus on surveillance and espionage activities, potentially targeting individuals or organizations involved in sensitive sectors. The specific motivation and strategic objectives of Nazar remain underdetermined due to limited available information.
Enhanced Description
Nazar is a cyber threat actor identified by Juan Andrés Guerrero-Saade as part of the SIG37 cluster in the ShadowBrokers' 'Lost in Translation' leak. The actor's name originates from a debug string fragment ('khzer') found in their malware. Nazar has been observed since 2008, with confirmed activity between 2010 and 2013. Their primary toolset includes a dropper that registers multiple DLLs as OLE controls in the Windows registry to facilitate keylogging, screen and sound capture, and network traffic interception through the MicroOlap Packet Sniffer library.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
To date, specific campaigns attributed to Nazar remain undefined. The actor's operational activity during 2010-2013 suggests a focus on establishing persistence in targeted systems and conducting long-term surveillance activities. While the exact scope of their operations is unclear, the use of MicroOlap Packet Sniffer indicates potential interest in monitoring network traffic for sensitive information.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis of Nazar is based on low confidence due to the lack of detailed information regarding their specific targeting, goals, and campaign details. While technical aspects of their toolset are well-documented, uncertainty persists about their broader operational scope and strategic motivations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
2
IOCs
0
Observed Data
0
Tactics