Sosano is a newly identified Go-based backdoor DLL reported by Proofpoint in connection with a highly targeted spearphishing campaign in fall 2024 attributed to the cluster UNK_CraftyCamel. The campaign affected fewer than five organizations in the United Arab Emirates, specifically entities associated with aviation, satellite communications, and critical transportation infrastructure. Delivery used a compromised email account at Indian electronics company INDIC Electronics and a lookalike domain, indicelectronics[.]net, to host a malicious ZIP archive. The infection chain used a disguised LNK file with a double extension, a PDF/HTA polyglot, and a PDF/ZIP polyglot. The LNK launched cmd.exe and mshta.exe, the HTA carved an executable and URL file from the appended ZIP content, established registry-based persistence via the URL file, and launched Hyper-Info.exe. Hyper-Info.exe located an XOR-obfuscated file named sosano.jpg and decoded it with the string 1234567890abcdef into a DLL the developer called yourdllfinal.dll, which Proofpoint named Sosano. Additional embedded strings abcdef1234567890 and 0fedcba987654321 were assessed as possible additional XOR keys. Sosano is approximately 12 MB in size and was assessed to be deliberately bloated with unused Golang libraries to complicate analysis. It performs a randomized sleep using time_Now() as a PRNG seed and math_rand_Intn() to evade sandboxing and defensive analysis. The malware communicates over HTTP with command-and-control infrastructure at bokhoreshonline[.]com, periodically issuing HTTP GET requests and executing returned commands. Documented commands include sosano for getting or changing directory, yangom for listing directory contents, monday for downloading and loading additional payloads, raian for deleting a directory, and lunna for executing shell commands. It could also download and execute a next-stage payload named cc[.]exe, although that payload was not recovered. At the time of analysis, indicelectronics[.]net resolved to 46.30.190[.]96 and bokhoreshonline[.]com resolved to 104.238.57[.]61; both IPs were hosted by CrownCloud. Proofpoint reported no direct overlap between UNK_CraftyCamel and other tracked clusters, but noted possible Iranian-aligned connections and TTP similarities with suspected IRGC-aligned TA451 and TA455 activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The resulting payload, the Sosano backdoor written in Go and deliberately bloated with unused libraries, communicated with actor-controlled infrastructure...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
"the PDF files were both polyglots; the first, a PDF file appended with an HTA while the second PDF file had a ZIP archive appended."
Defense evasion has remained a critical phase, where threat actors employ multiple obfuscation techniques (T1140) and masquerading (T1036) to bypass security controls.
"the JPG gets XORed with the string '1234567890abcdef' and decodes to a DLL ... which is the backdoor Proofpoint named Sosano."
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based backdoor delivered via polyglot files in a supply-chain-themed campaign against UAE aerospace, transport, and satellite navigation organizations.
Custom Golang DLL backdoor delivered via a multistage spearphishing chain using LNK + PDF/HTA and PDF/ZIP polyglot files. It sleeps for a randomized interval, then beacons to C2 over HTTP GET and supports basic remote commands (directory operations, shell execution) and downloading/loading additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.