ESET researchers reported that the Iran-aligned threat group Ballistic Bobcat used a custom backdoor called Sponsor in operations that combined internet-wide scanning with rapid post-compromise deployment. The malware was delivered through batch scripts, giving the group a lightweight way to establish persistence and remote access on compromised systems while moving quickly from target discovery to intrusion.
The activity highlights an intrusion pattern in which attackers pair broad reconnaissance with simple but effective tooling to convert exposed services into footholds. By using scripted deployment and a bespoke backdoor, Ballistic Bobcat was able to streamline access operations and maintain control over victim environments, underscoring the ongoing risk from state-linked actors that rely on low-complexity initial execution methods backed by tailored malware.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET released a report detailing Ballistic Bobcat activity involving the Sponsor backdoor, including the group's scan-and-strike tradecraft and use of batch-file techniques. The publication marks the public disclosure of the campaign's technical details.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.