Actors Insights|Latest update04/07/2026

UNK_CraftyCamel

Named by ProofpointSuspected state sponsor: Islamic Republic of Iran

UNK_CraftyCamel is a Proofpoint tracking designation for a suspected Iranian-aligned threat actor first documented in October 2024, targeting aviation, satellite communications, and critical transportation infrastructure organizations in the United Arab Emirates. The group compromised the email account of an Indian electronics company (INDIC Electronics) that had an existing business relationship with its targets, then sent malicious emails from that trusted account to fewer than five high-value UAE organizations. The attack chain used polyglot files — files interpretable as multiple formats simultaneously — to evade detection, ultimately delivering Sosano, a custom Golang-based backdoor that supports directory listing, file execution, and additional payload download via an HTTP command and control channel. Proofpoint assessed UNK_CraftyCamel as a distinct cluster with no direct overlap with previously tracked groups, but noted significant TTP similarities with IRGC-affiliated actors TA451 and TA455, particularly in the use of HTA files and business-to-business sales lures targeting aerospace engineers in the UAE.

First Seen:Oct 2024
Last Seen:Feb 2025
Indexed Reports:1
Public IOCs:9
Cluster: Unclassified
also known as:
UNK_CraftyCamel

Targeted Regions

United Arab Emirates
AE
United Arab Emirates
United Arab Emirates
Oct 2024 ~ Feb 2025
Oct 2024 ~ Feb 2025
Oct 2024 ~ Feb 2025
Oct 2024 ~ Feb 2025
Jan 2024Nov 2026

Targeted Sectors

ManufacturingAerospaceTelecommunicationTransportation

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.