UNK_CraftyCamel Targets UAE Aviation and Infrastructure with Polyglot Malware
- Actor Motivations: Espionage,Undetected
- Attack Vectors: Backdoor,Spyware,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
In fall 2024, UNK_CraftyCamel — a newly identified threat cluster with suspected Iranian-aligned ties — targeted fewer than five organizations in the United Arab Emirates with a focus on aviation, satellite communications, and critical transportation infrastructure. The attackers gained access to the email account of INDIC Electronics, an Indian electronics company with existing business relationships with the targets, and used it to send highly customized spearphishing emails. The messages directed recipients to a lookalike domain (indicelectronics[.]net) that served a malicious ZIP archive. The archive appeared to contain an XLS file and two PDFs, but was constructed using polyglot techniques: the XLS was actually an LNK file with a double extension, and both PDFs carried hidden payloads — one appended with an HTA script (the orchestrator) and the other with a ZIP containing the final backdoor. The LNK executed cmd.exe and mshta.exe to run the HTA, which carved out and launched Hyper-Info[.]exe. That loader XOR-decoded a file named sosano.jpg (using the key "1234567890abcdef") into a Golang DLL backdoor — named Sosano by Proofpoint — which established persistence via a registry URL run key and communicated with its C2 at bokhoreshonline[.]com. Sosano supports directory enumeration, file download and execution, shell command execution, and directory deletion. Proofpoint notes TTP similarities with Iranian IRGC-aligned groups TA451 and TA455 but tracks UNK_CraftyCamel as an independent cluster.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | INDIC Electronics INDIC Electronics has been targeted by UNK_CraftyCamel with abusive purposes. | Verified |
| Sector | Manufacturing | Verified |
| Sector | Aerospace | Verified |
| Sector | Telecommunication None | Verified |
| Sector | Transportation | Verified |
| Region | United Arab Emirates | Verified |
Extracted IOCs
- bokhoreshonline[.]com
- indicelectronics[.]net
- 0ad1251be48e25b7bc6f61b408e42838bf5336c1a68b0d60786b8610b82bd94c
- 0c2ba2d13d1c0f3995fc5f6c59962cee2eb41eb7bdbba4f6b45cba315fd56327
- 336d9501129129b917b23c60b01b56608a444b0fbe1f2fdea5d5beb4070f1f14
- 394d76104dc34c9b453b5adaf06c58de8f648343659c0e0512dd6e88def04de3
- e692ff3b23bec757f967e3a612f8d26e45a87509a74f55de90833a0d04226626
- 104[.]238.57.61
- 46[.]30.190.96
Tip: 9 related IOCs (2 IP, 2 domain, 0 URL, 0 email, 5 file hash) to this threat have been found.
FAQs
Frequently Asked Questions about UNK_CraftyCamel's Polyglot Malware Campaign in the UAE
In fall 2024, a threat group tracked as UNK_CraftyCamel carried out a highly targeted cyberattack against a small number of organizations in the United Arab Emirates. The attackers compromised the email account of a legitimate Indian electronics supplier (INDIC Electronics) that had existing business relationships with the targets. Using that trusted account, they sent customized phishing emails containing a malicious ZIP file. The ZIP looked like routine business documents but hid a sophisticated multi-stage malware chain that ultimately installed a custom backdoor called Sosano on victims' computers. The campaign was discovered and reported by Proofpoint in February 2025.
The attack was carried out by a group Proofpoint tracks as UNK_CraftyCamel — a newly identified threat cluster. The group has not yet been formally attributed to a named state actor, but Proofpoint noted significant TTP overlaps with Iranian IRGC-aligned groups TA451 and TA455, which historically target aerospace and defense organizations. Broader infrastructure analysis by trusted partners also indicated possible connections with Iranian-aligned adversaries. Proofpoint currently tracks UNK_CraftyCamel as a separate, independent cluster from these groups.
The campaign's goal was espionage — gaining persistent, covert access to the networks of high-value organizations in the UAE's aviation, satellite communications, and transportation sectors. The Sosano backdoor installed on victims' machines gave the attackers the ability to browse files and directories, execute commands, and download additional payloads. The use of sophisticated obfuscation and an emphasis on staying hidden suggests the attackers had a clear mandate for long-term, stealthy intelligence collection rather than disruptive action.
The campaign was exceptionally narrow — Proofpoint identified fewer than five targeted organizations, all in the UAE. This precision is consistent with a state-directed intelligence operation with specific targets in mind, rather than a broad criminal campaign. Each phishing email was customized to its specific recipient, further demonstrating the operator's careful, targeted approach.
The targets were organizations in the UAE's aviation, satellite communications, and critical transportation infrastructure sectors. These industries sit at the intersection of national security and strategic economic interests — aviation and satellite communications provide intelligence on troop movements, logistics, and surveillance capabilities, while transportation infrastructure underpins the movement of people and goods across the region. For an actor aligned with Iranian state interests, access to these sectors would provide significant strategic intelligence about UAE and allied operations.
The attack chain was unusually complex. First, the attackers compromised a supplier's email account and sent targeted emails linking to a malicious ZIP file hosted on a lookalike domain. The ZIP appeared to contain normal business documents, but the files were polyglots — files engineered to appear as one format (like a PDF) while secretly containing a second format (like an HTA script or ZIP archive) that executes malicious code. Opening the fake XLS file triggered a chain: cmd.exe launched mshta.exe, which executed the hidden HTA script, which extracted and ran a loader called Hyper-Info.exe. That loader decoded a hidden file (disguised as a JPG image) using an XOR key to reveal the Sosano backdoor — a custom Golang malware — which then installed itself persistently and connected to the attacker's command-and-control server.
UAE aviation and satellite communications organizations are attractive targets because they hold sensitive operational data — flight routes, cargo manifests, satellite coverage maps, and communications infrastructure details — that have direct military and intelligence value. For an actor with suspected Iranian ties, the UAE represents both a geopolitical rival and a hub for US and allied military logistics in the region. Compromising these sectors could yield real-time intelligence on regional operations and provide strategic advantage in an ongoing geopolitical competition.
Organizations should treat files from known business partners with the same scrutiny as unsolicited emails — especially when a ZIP or document arrives unexpectedly. When in doubt, verify through a separate channel (phone or a known-good email address) before opening. Security teams should block or alert on LNK files executing from unzipped directories, mshta.exe processes launched by cmd.exe, and registry Run key entries pointing to URL files. Block the known IOCs: indicelectronics[.]net, bokhoreshonline[.]com, 46.30.190[.]96, and 104.238.57[.]61. Aviation, satellite, and transportation organizations in the UAE and Gulf region should deploy email sandboxing, domain lookalike detection, and user awareness training focused on supply chain phishing. Proofpoint ET rules 2060036–2060039 are available for network-level detection.