Nazar is a suspected Middle East–linked espionage threat activity cluster publicly named from analysis of an Equation Group Territorial Dispute signature associated with the malware artifact Godown.dll. Reporting places its known activity roughly between 2008 and 2012, with some assessments suggesting an Iranian nexus. Nazar has been characterized as a relatively unsophisticated but functional remote-access operation built heavily from commodity and open-source components rather than novel tradecraft. The intrusion chain associated with Nazar begins with a self-extracting dropper that reconstructs and deploys multiple components, registers several DLL modules, and installs a Windows service used as the primary remote-access implant. The main implant dispatches commands to supporting modules that provide keylogging, screenshot capture, microphone recording, drive and file enumeration, installed-program and device discovery, file theft, file deletion, host information collection, and system shutdown. The malware family also includes dedicated modules for filesystem interaction, screen capture, keystroke logging, and shutdown functionality. A notable aspect of Nazar’s command-and-control design is its use of local packet sniffing to monitor UDP traffic and process commands based on packet characteristics rather than relying on a conventional hard-coded command-and-control address in the analyzed component. Responses can include host metadata and exfiltrated file contents. This design, while unusual, does not appear to reflect especially advanced engineering; analyses have noted extensive reuse of publicly available libraries and code for packet capture, MP3 encoding, keyboard hooks, graphics handling, and shutdown functionality. Nazar has been associated with activity in the Middle East and has been discussed alongside other advanced persistent threat operations active in that region. Although earlier analysis reportedly misidentified it as Chinese-linked, later assessments more strongly pointed toward an Iranian connection. High-confidence public reporting does not establish a broader alias set or clearly defined sub-groups beyond the Nazar designation itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An espionage-oriented RAT/backdoor activity cluster active roughly 2008-2012, using a modular toolset for keylogging, screenshots, microphone recording, file enumeration, file theft, device/program listing, and remote shutdown over a custom UDP-based C2 channel.
Named APT activity possibly linked to the Middle East, retrospectively associated with SIG37 and active as early as 2008.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.