[ << ALL_FEED ]

Desert Dexter is a group targeting residents of Arab states.

More in General

Desert Dexter — a group targeting residents of Arab states👽

Specialists from the cyber intelligence group of the PT ESC TI department have discovered a malicious campaign targeting residents of the Middle East and North Africa, active since September 2024.

👾 The malware used is AsyncRAT, employing a modified IdSender module that collects information about the presence of two-factor authentication extensions, cryptocurrency wallet extensions in browsers, as well as the presence of software for working with them.

To distribute AsyncRAT, the attackers create fake news groups on social networks and publish posts with advertisements. These posts contain links to file-sharing services or Telegram channels where the malware is located.

🔍 During the investigation, we discovered about 900 potential victims, most of whom are ordinary users.

A detailed study of the incidents and affected parties showed that the most targeted countries are Egypt 🇪🇬, Qatar 🇶🇦, Libya 🇱🇾, UAE 🇦🇪, Saudi Arabia 🇸🇦, and Turkey 🇹🇷. We named the group Desert Dexter, after one of the suspects.

👤 We also found that the attackers create temporary accounts and news channels on Facebook* and bypass advertising filtering rules. A similar attack was described in 2019 by Check Point experts, but now a change in some of its techniques is being observed.

🐃 Learn more about the attack chain prepared by Desert Dexter in the research on our website here.

*Belongs to Meta, which is recognized as an extremist organization and banned in Russia.

#TI #APT #malware
@ptescalator

More from ti_author

More from ti_author

More in General