Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: SIG37

Description

This actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation' leak. Earliest known sighting potentially dates back to as far as 2008 with a confirmed center of activity around 2010-2013. The actor name is derived from a PDB debug string fragment: 'khzer'. Victimology indicates targeting of Iran, assessed with low confidence based on VT file submission locations. Nazar employs a modular toolkit where a main dropper silently registers multiple DLLs as OLE controls in the Windows registry. Functionality includes keylogging, sound and screen grabbing, as well as traffic capture using the MicroOlap Packet Sniffer library.

AI Analysis

· 1 week ago

Executive Summary

Nazar, also known as SIG37, is a potentially long-standing cyber threat actor identified through the ShadowBrokers' 'Lost in Translation' leak. The actor has been observed since 2008 but was most active between 2010 and 2013. Nazar employs a modular toolkit for surveillance activities including keylogging, screen and sound capture, and network traffic interception using the MicroOlap Packet Sniffer library.

Goals & Targeting

While Nazar's broader targeting strategy remains unclear, there is low-confidence intelligence suggesting an interest in victims within Iran. The actor's modular toolkit suggests a focus on surveillance and espionage activities, potentially targeting individuals or organizations involved in sensitive sectors. The specific motivation and strategic objectives of Nazar remain underdetermined due to limited available information.

Enhanced Description

Nazar is a cyber threat actor identified by Juan Andrés Guerrero-Saade as part of the SIG37 cluster in the ShadowBrokers' 'Lost in Translation' leak. The actor's name originates from a debug string fragment ('khzer') found in their malware. Nazar has been observed since 2008, with confirmed activity between 2010 and 2013. Their primary toolset includes a dropper that registers multiple DLLs as OLE controls in the Windows registry to facilitate keylogging, screen and sound capture, and network traffic interception through the MicroOlap Packet Sniffer library.

Key Capabilities

  • Modular malware toolkit with OLE control registry manipulation
  • Keylogging functionality for credential theft
  • Screen and sound recording capabilities
  • Network traffic capture using MicroOlap

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Defense Evasion

ATT&CK Techniques

T1566.003
T1070
T1055

Software / Tooling

Nazar Dropper
MicroOlap Packet Sniffer
Custom OLE Controls Registry Malware

Campaigns & Victims

To date, specific campaigns attributed to Nazar remain undefined. The actor's operational activity during 2010-2013 suggests a focus on establishing persistence in targeted systems and conducting long-term surveillance activities. While the exact scope of their operations is unclear, the use of MicroOlap Packet Sniffer indicates potential interest in monitoring network traffic for sensitive information.

IOC Patterns

  • Registry entries with OLE controls
  • File hashes associated with Nazar dropper
  • Network traffic patterns indicative of packet sniffer usage
  • MicroOlap process or DLL activity

Recommended Actions

  • Implement network monitoring for anomalous traffic patterns that may indicate the use of a packet sniffer.
  • Conduct regular audits of system registries to identify and remove malicious OLE controls.
  • Enhance email filtering and endpoint protection to detect potential payloads from phishing or other delivery mechanisms.
  • Monitor for and block communication to domains associated with known threat actor infrastructure.

Suggested Tags

APT
espionage
surveillance
low_confidence_geographic_targeting

Confidence Assessment

The analysis of Nazar is based on low confidence due to the lack of detailed information regarding their specific targeting, goals, and campaign details. While technical aspects of their toolset are well-documented, uncertainty persists about their broader operational scope and strategic motivations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
surveillance
low_confidence_geographic_targeting

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.