Fortinet and SANS researchers detailed a targeted spearphishing intrusion against a Jordanian diplomat and foreign ministry official that was assessed as likely linked to Iranian threat group APT34. The attack delivered a malicious Excel attachment whose macro used unusual tradecraft, including worksheet-visibility toggling, a mouse-presence check, WMI-based state check-ins, and scheduled-task persistence before dropping a .NET backdoor and related files into %LocalAppData%\MicrosoftUpdate\. Researchers said the malware’s command set indicated prior knowledge of the victim environment, supporting the assessment that the operation was a tailored espionage intrusion rather than commodity phishing.
The backdoor, identified as Saitama, used a domain generation algorithm (DGA) and DNS tunneling for command-and-control and data theft. Unlike many DNS-tunneling implants that rely on TXT records, Saitama encoded C2 instructions inside IPv4 addresses returned in DNS responses, while infected hosts split and sent exfiltrated data across multiple DNS requests. Analysis of the malware showed it could perform reconnaissance, execute commands through PowerShell and CMD, and use a mutex to avoid multiple concurrent instances; researchers also published tooling to decode Saitama’s DNS traffic and reconstruct stolen host data such as Windows version information.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
SANS ISC published an analysis of Saitama's DNS tunneling, explaining how the malware encoded commands inside IPv4 addresses rather than TXT records and showing decoded examples of exfiltrated data. The write-up also linked Saitama to the phishing attack against a Jordanian foreign ministry official and to APT34 attribution.
FortiGuard Labs disclosed technical analysis of the phishing campaign, describing the Excel macro, scheduled-task persistence, .NET backdoor, and DNS-tunneling command-and-control. The report highlighted themed domains and victim-environment reconnaissance that supported its APT34 assessment.
Two additional domains tied to the malware infrastructure, asiaworldremit.com and uber-asia.com, were registered on February 27, 2022. The report says they later resolved to 193.239.84.207 and 127.0.0.1 respectively before both were pointed to 127.0.0.1.
The command-and-control domain joexpediagroup.com used in the campaign was created on January 20, 2022. The report says it previously resolved to 45.11.19.47 before later resolving to 127.0.0.1.
After analyzing Saitama's code, Morphus Labs created a tool called saitama_translator to decode or reconstruct messages exfiltrated by infected hosts through DNS queries. The tool was made available through a GitHub repository referenced in the analysis.
A phishing email impersonating an IT colleague targeted a diplomat in Jordan and delivered a malicious Excel attachment named "Confirmation Receive Document.xls." FortiGuard Labs assessed the intrusion as likely linked to APT34 and designed to steal sensitive information from the victim's Windows system.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.