MalKamak

Also known as: MalKamak

MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.

🌍 Country Iran

Introduction

MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.

Activities and Tactics

Country of Origin: 🇮🇷 Iran

Notable Campaigns

  • Operation GhostShell

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • SPACESHIP
  • CloudDuke
  • Trojan.Karagany
  • RemoteCMD
  • Trojan.Mebromi
  • ClientMesh
  • CyberGate
  • Cyber Eye RAT
  • Virus RAT
  • Remote Utilities
  • ShellClient:

Attribution and Evidence

Country of Origin: Iran Additional attribution information pending cataloguing.

References

References pending cataloguing.