Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors MalKamak

Description

MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.

AI Analysis

· 1 week ago

Executive Summary

MalKamak is an Iranian threat actor known for conducting cyber espionage campaigns targeting global aerospace and telecommunications companies. They employ a sophisticated remote access Trojan (RAT) called ShellClient, which evades antivirus detection and leverages cloud services like Dropbox for command and control. MalKamak's activities have been ongoing since at least 2018, and their operations suggest a high level of technical expertise.

Goals & Targeting

MalKamak's primary goal appears to be cyber espionage, with an emphasis on stealing sensitive data from targeted industries. Their selection of aerospace and telecommunications sectors suggests a desire to acquire strategic information that could impact national security and global market dynamics. The actor likely targets these sectors due to the high value of intellectual property and the potential for significant disruption if such information were compromised.

Enhanced Description

MalKamak operates as a cyber espionage group targeting sensitive industries such as aerospace and telecommunications. Their use of the ShellClient RAT indicates advanced capabilities in evading detection and maintaining persistent access to targeted systems. The actor employs cloud services for command and control, making their activities harder to detect by blending malicious traffic with legitimate service usage. MalKamak's campaigns are highly strategic, focusing on sectors that hold valuable intellectual property and geopolitical significance. Their targeting patterns suggest a focus on global companies, likely aiming to gather intelligence for economic or military advantage.

Key Capabilities

  • Sophisticated remote access Trojan (RAT) deployment
  • Cloud service abuse for command and control
  • Advanced evasion techniques to bypass antivirus tools
  • Targeted phishing campaigns with malicious payloads

MITRE ATT&CK Tactics

Network
Reconnaissance
Exfiltration
Credential Access

ATT&CK Techniques

T1074
T1562.003
T1566
T1059

Software / Tooling

ShellClient RAT

Campaigns & Victims

MalKamak has been linked to multiple cyber espionage campaigns since 2018, primarily targeting aerospace and telecommunications companies. Their campaigns exhibit a patient and calculated approach, with a focus on long-term access and data collection. The actor's use of cloud-based command and control infrastructure suggests an effort to avoid traditional detection mechanisms while maintaining persistent access.

IOC Patterns

  • Spear-phishing emails targeting specific industries
  • Malicious Office documents as payload delivery vehicles
  • C2 communication via legitimate cloud services
  • Abnormal file uploads or network traffic associated with ShellClient

Recommended Actions

  • Implement robust email filtering and phishing detection solutions
  • Monitor for suspicious activity in cloud service accounts
  • Conduct regular security audits and vulnerability assessments
  • Enhance network monitoring for异常external communication patterns
  • Educate employees on identifying targeted phishing attempts
  • Incorporate advanced threat detection tools to identify RAT activities

Suggested Tags

APC
Espionage
Aerospace
Telecommunications
Cyber_Espionage

Confidence Assessment

Moderate confidence in MalKamak's attributes, with gaps remaining in the exact TTPs beyond general behaviors. Further analysis of their cloud service usage and specific C2 infrastructure could enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
APC
Espionage
Aerospace
Telecommunications
Cyber_Espionage

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.