A likely state-backed cyberespionage campaign targeted Libyan organizations including an oil refinery, an oil company network, a telecommunications entity, and a state institution, using politically themed spear-phishing emails to deliver the AsyncRAT remote access trojan. Researchers said the operation ran from November 2025 to mid-February 2026, with related files suggesting activity may have begun as early as April 2025. The lures referenced Libya-specific political events, including reports about the killing of Saif al-Islam Gaddafi, indicating deliberate targeting tied to local developments.
The intrusion chain used a VBS downloader, a PowerShell dropper, and persistence through a scheduled task named devil before deploying AsyncRAT, which can enable keystroke logging, screen capture, credential theft, and remote command execution. Investigators said the victimology, duration, and tradecraft point to espionage rather than financially motivated crime, and noted overlaps with prior Middle East activity linked to Iran-associated MuddyWater, though no definitive attribution was made.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On publication of the reports, researchers publicly detailed the likely espionage campaign, its Libya-themed lures, victim sectors, and technical overlap with prior Middle East activity associated with MuddyWater. They assessed the operation as likely state-sponsored but did not make a definitive attribution.
Researchers said the campaign against at least one Libyan oil-sector target continued until mid-February 2026, suggesting a multi-month compromise. The intrusion used VBS and PowerShell components plus a scheduled task for persistence before deploying AsyncRAT.
Between November 2025 and February 2026, attackers targeted Libyan organizations including an oil refinery, an oil company network, a telecommunications organization, and a state institution. The campaign used politically themed spear-phishing emails and a multi-stage infection chain to deploy the AsyncRAT remote access Trojan.
Researchers found related files on VirusTotal dating back to April 2025, indicating the broader operation targeting Libyan entities may have started earlier than the main observed intrusion window. The activity appeared focused on Libyan targets from an early stage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurity.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.