MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.
Executive Summary
MalKamak is an Iranian threat actor known for conducting cyber espionage campaigns targeting global aerospace and telecommunications companies. They employ a sophisticated remote access Trojan (RAT) called ShellClient, which evades antivirus detection and leverages cloud services like Dropbox for command and control. MalKamak's activities have been ongoing since at least 2018, and their operations suggest a high level of technical expertise.
Goals & Targeting
MalKamak's primary goal appears to be cyber espionage, with an emphasis on stealing sensitive data from targeted industries. Their selection of aerospace and telecommunications sectors suggests a desire to acquire strategic information that could impact national security and global market dynamics. The actor likely targets these sectors due to the high value of intellectual property and the potential for significant disruption if such information were compromised.
Enhanced Description
MalKamak operates as a cyber espionage group targeting sensitive industries such as aerospace and telecommunications. Their use of the ShellClient RAT indicates advanced capabilities in evading detection and maintaining persistent access to targeted systems. The actor employs cloud services for command and control, making their activities harder to detect by blending malicious traffic with legitimate service usage. MalKamak's campaigns are highly strategic, focusing on sectors that hold valuable intellectual property and geopolitical significance. Their targeting patterns suggest a focus on global companies, likely aiming to gather intelligence for economic or military advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
MalKamak has been linked to multiple cyber espionage campaigns since 2018, primarily targeting aerospace and telecommunications companies. Their campaigns exhibit a patient and calculated approach, with a focus on long-term access and data collection. The actor's use of cloud-based command and control infrastructure suggests an effort to avoid traditional detection mechanisms while maintaining persistent access.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in MalKamak's attributes, with gaps remaining in the exact TTPs beyond general behaviors. Further analysis of their cloud service usage and specific C2 infrastructure could enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics