Kaspersky reported that the DeathStalker threat actor used a new Janicab malware variant to target legal entities, financial institutions, and possibly travel agencies across the Middle East and Europe, with activity observed through 2020 and likely continuing into 2021. Victims were concentrated in Egypt, Georgia, Saudi Arabia, the United Arab Emirates, and the United Kingdom, and the report noted Saudi legal entities among the targets for the first time.
The campaign relied on spear-phishing emails carrying ZIP archives with malicious .LNK droppers that launched chained VBE/VBS stages, unpacked a CAB archive containing Python-based tools, and established persistence on infected systems. The malware resolved command-and-control infrastructure through dead-drop resolvers hosted on public services including YouTube, and researchers linked the operation to other DeathStalker toolsets such as PowerSing, EVILNUM, and PowerPepper through shared tactics, infrastructure, anti-analysis logic, and tools including a Stormwind keylogger and an ICMP shell; the implant supported command execution, screenshots, keylogging, proxying, FTP access, and reverse SSH tunneling.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
The report says the Janicab campaign was likely still active during 2021, with intrusions reusing old unlisted YouTube links as dead-drop resolvers to obtain command-and-control infrastructure.
Throughout 2020, DeathStalker used a newer Janicab variant in spear-phishing intrusions targeting legal entities in the Middle East, as well as financial institutions and possibly travel agencies in the Middle East and Europe. The activity affected victims in Egypt, Georgia, Saudi Arabia, the United Arab Emirates, and the United Kingdom.
DeathStalker has targeted legal, financial, and travel-related organizations in the Middle East and Europe since at least early 2015.
The Janicab malware family was first introduced as malware capable of running on both macOS and Windows.
The reporting identified legal entities in Saudi Arabia as Janicab victims, marking the first time such targets in Saudi Arabia were noted in this reporting.
Securelist reported with high confidence that the newer Janicab variant was associated with the DeathStalker threat actor, citing overlaps in TTPs, infrastructure, anti-analysis logic, and tooling with other DeathStalker malware families.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.