UnsolicitedBooker is a China-aligned threat activity cluster assessed to be active since at least March 2023. It has been observed targeting telecommunications organizations in Kyrgyzstan and Tajikistan, representing a shift from earlier targeting of Saudi Arabian entities (and more broadly organizations in Asia, Africa, and the Middle East). Reported initial access commonly involves phishing emails delivering malicious Microsoft Office documents that prompt victims to enable macros; the macros deploy loaders (e.g., LuciLoad or MarsSnakeLoader) that install corresponding backdoors. UnsolicitedBooker has deployed at least two backdoors: LuciDoor (C++) and MarsSnake. These implants provide system reconnaissance/metadata collection, command-and-control communications, arbitrary command execution (e.g., via cmd.exe), file read/write, and data exfiltration (including encrypted exfiltration of system information). In some cases, the actor used alternative execution chains involving Windows shortcut (LNK) files masquerading as documents (e.g., *.doc.lnk) that execute batch and VBScript stages to launch MarsSnake; this LNK tradecraft was assessed as resembling publicly available tooling (FTPlnk_phishing) and has similarities to prior Mustang Panda LNK usage. The cluster has been reported to use several unique/rare tools of Chinese origin, show tactical overlaps with the Space Pirates cluster, and in at least one instance used a compromised/hacked router as command-and-control infrastructure; some observed infrastructure also mimicked Russia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned intrusion cluster conducting espionage-style intrusions, shifting targeting from Saudi Arabian entities to telecommunications providers in Kyrgyzstan and Tajikistan; uses phishing with malicious Office documents and macro-enabled loaders to deploy LuciDoor and MarsSnake backdoors for system discovery, command execution, and data exfiltration; has used compromised routers for C2 and tooling overlaps with other clusters.
China-aligned espionage activity cluster conducting phishing-led intrusions (malicious Office docs/macros and LNK-based execution chains) to deploy custom backdoors (LuciDoor, MarsSnake) against telecom and other organizations; observed shifting targeting from Saudi Arabia to Kyrgyzstan/Tajikistan, with some indications of MarsSnake used in attacks targeting China.
ESET-tracked Chinese-linked APT referenced as potentially related to a campaign targeting telecoms in Kyrgyzstan and Tajikistan using LuciDoor and MarsSnake backdoors.
China-aligned actor conducting multi-year intrusion against an organization in Saudi Arabia; used spear-phishing and deployed MarsSnake backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.