Metador is an advanced, long-running espionage-focused threat actor of unknown origin. It has primarily targeted telecommunications providers, internet service providers, and universities across the Middle East and Africa. No reliable attribution to a specific state or country has been established; available evidence is also consistent with a high-end contractor-style operation. Metador demonstrates strong operational security, including victim-specific and segmented command-and-control infrastructure, rapid adaptation to security tooling, encrypted payloads, in-memory execution, and rapid deletion of deployment artifacts. Its known Windows malware platforms include metaMain and Mafalda, with Cryshell used to relay indirect command-and-control communications. Evidence also indicates an associated Linux implant used for proxying and collecting data from Linux systems. Metador established persistence through WMI event subscriptions and abused Microsoft Console Debugger as a living-off-the-land binary to decrypt malware, inject shellcode into a legitimate process, and execute implants in memory. metaMain supports long-term access, keylogging, mouse-event logging, screenshot capture, file transfer, and arbitrary shellcode execution. Mafalda is an actively maintained interactive backdoor with more than 60 commands, host-environment collection, anti-analysis functionality, and HTTP and raw-TCP command-and-control support. The actor's tradecraft indicates an emphasis on maintaining redundant, durable access while minimizing on-host activity and forensic exposure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
Listed in the detection annotation metadata.
Listed only as an annotation associated with the detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.