UNK_CraftyCamel
Named by ProofpointSuspected state sponsor: Islamic Republic of IranUNK_CraftyCamel is a Proofpoint tracking designation for a suspected Iranian-aligned threat actor first documented in October 2024, targeting aviation, satellite communications, and critical transportation infrastructure organizations in the United Arab Emirates. The group compromised the email account of an Indian electronics company (INDIC Electronics) that had an existing business relationship with its targets, then sent malicious emails from that trusted account to fewer than five high-value UAE organizations. The attack chain used polyglot files — files interpretable as multiple formats simultaneously — to evade detection, ultimately delivering Sosano, a custom Golang-based backdoor that supports directory listing, file execution, and additional payload download via an HTTP command and control channel. Proofpoint assessed UNK_CraftyCamel as a distinct cluster with no direct overlap with previously tracked groups, but noted significant TTP similarities with IRGC-affiliated actors TA451 and TA455, particularly in the use of HTA files and business-to-business sales lures targeting aerospace engineers in the UAE.
Targeted Regions
United Arab EmiratesUnited Arab Emirates
Oct 2024 ~ Feb 2025
Oct 2024 ~ Feb 2025
Oct 2024 ~ Feb 2025
Oct 2024 ~ Feb 2025
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.