UnsolicitedBooker: this unsolicited boxer with 1 rep will go down

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
UnsolicitedBooker: this uninvited boxer with 1 report will go down 🥊
In the fall of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center discovered attacks on telecommunications companies in Kyrgyzstan. The attackers sent targeted phishing emails containing malicious documents with macros. Already at this stage, attention was drawn to the use of unusual tools of Chinese origin within the documents themselves.
The attackers used two backdoors as malware. The first — MarsSnake — was previously mentioned only in a quarterly report by ESET. The second — LuciDoor, which we named due to the unusual feature of setting the Lucida Console 11×18 font for correct text display in the terminal.
👋 In 2026, the attackers resurfaced, but this time with attacks on telecommunications companies in Tajikistan. We attribute this activity to the East Asian group UnsolicitedBooker. Previously, according to researchers’ observations, the group attacked Saudi Arabia.
In our article we detailed the detected attacks, fully analyzed the functionality of LuciDoor and MarsSnake, and showed which common tool is used by UnsolicitedBooker and Mustang Panda 🐼
#TI #APT #Malware
@ptescalator
💬 X 💬 Max
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



