Researchers detailed Attor, a modular cyberespionage malware platform used against a small number of highly targeted victims, including diplomats, government institutions, and Russian-speaking users in Russia and Eastern Europe. ESET said the operation had been active since at least 2013, with another observed wave beginning in 2018 and continuing into mid-2019, and described the tooling as consistent with a focused intelligence-gathering campaign rather than broad criminal activity.
The malware centers on a dispatcher component and encrypted plugins protected with RSA-based asymmetric encryption. Recovered modules support screenshots, audio recording, keylogging, clipboard logging, file upload, SOCKS proxying, device monitoring, persistence, and Tor-assisted communications to an FTP command-and-control server on an onion domain. Researchers highlighted an unusual GSM fingerprinting plugin that sends legacy AT commands over serial/COM ports to identify connected modems, older phones, or specialized GSM equipment, suggesting operators sought detailed profiling of attached devices for follow-on espionage activity.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
ESET said the later Attor activity wave continued through July 2019, extending the known operational window for the malware's more recent campaign activity.
ESET observed another wave of Attor activity beginning in 2018, indicating continued use of the malware platform in targeted espionage campaigns.
ESET reported that the Attor malware family has been used since at least 2013 in targeted espionage operations against a narrow set of victims, including diplomats, government institutions, and Russian-speaking users in Russia and Eastern Europe.
ESET published research disclosing the Attor malware family, describing its modular architecture, espionage-focused plugins, and unusual GSM fingerprinting capability aimed at devices connected over serial COM ports.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.