Check Point Research reported that a November 2022 espionage campaign targeted entities in Armenia with an updated OxtaRAT backdoor, an AutoIt-based malware family previously seen in attacks on Azerbaijani activists and dissidents. The intrusion used a malicious .scr file disguised as a PDF and themed around Alexander Lapshin, then unpacked a polyglot payload hidden inside an image file to reduce detection and establish access on victim systems.
The latest OxtaRAT variant introduced stronger operational security and Armenian-IP geofencing, along with persistence through a scheduled task and expanded surveillance capabilities. Researchers said the malware could steal files, record webcams and desktops, remotely control infected machines through TightVNC, deploy a PHP web shell, scan ports, create tunnels, and conduct broader reconnaissance, linking the activity with medium confidence to threat actors aligned with Azerbaijani government interests.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point Research published its analysis of Operation Silent Watch, detailing the November 2022 OxtaRAT campaign, its expanded surveillance capabilities, and links to earlier activity aligned with Azerbaijani government interests.
Alexander Lapshin said Artsakhbank representatives reported receiving malicious emails in his name on the same day the malware samples were uploaded to VirusTotal. This tied the lure theme to real-world delivery activity against Armenian recipients.
A malicious .scr file masquerading as a PDF was submitted to VirusTotal from an IP address in Yerevan, Armenia. The sample used an Alexander Lapshin-themed lure and dropped the latest OxtaRAT infection chain.
In November 2022, threat actors conducted an espionage campaign against entities in Armenia using a new version of the AutoIt-based OxtaRAT backdoor. The activity marked a clear association of OxtaRAT with Armenian targets and corporate environments.
The domains edupoliceam[.]info and avvpassport[.]info were created and were later assessed as likely supporting attacks on Armenian targets in the OxtaRAT campaign.
On 2021-07-07, several prominent political and human rights activists in Azerbaijan received phishing emails impersonating Human Rights Watch and delivering a password-protected archive from Google Drive. The lure installed an AutoIT-based malware chain that fetched second-stage payloads from shoesbuysellone.live and enabled persistence, surveillance, command execution, and file exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcequrium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.