Threats Feed|APT34|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date10/05/2022

APT34 Targets Jordan's Government with Saitama Backdoor: A New Wave of Cyber Espionage

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Malwarebytes Threat Intelligence documents the discovery of Saitama, a new APT34 backdoor found in a spearphishing attack on April 26, 2022 against a government official at Jordan's Foreign Ministry. The malicious email was sent from a Microsoft Outlook account impersonating a Jordanian government official — using the Jordan coat of arms as a signature — with an Excel attachment named "Confirmation Receive Document.xls." The macro runs on WorkBook_Open(), uses a WMI Win32_PingStatus query (rather than standard DNS resolution) to beacon execution steps to the C2, implements a mouse-check anti-sandbox technique (only executing if a mouse is detected), creates a %APPDATA%/MicrosoftUpdate directory, writes three payload components (Update.exe, Update.exe.config, Microsoft.Exchange.WenServices.dll) decoded from Base64 UserForm labels, and establishes persistence via a scheduled task named "MicrosoftUpdate." The Saitama backdoor (PDB: E:\Saitama\Saitama.Agent\obj\Release\Saitama.Agent.pdb) is a .NET finite state machine with states: BEGIN, ALIVE (fetches C2 via PRNG-seeded Mersenne Twister subdomains), SLEEP/SECOND SLEEP (up to 6–8 hours on failed DNS), RECEIVE, DO, and SEND/SEND AND RECEIVE. Its 22 hardcoded predefined commands include network reconnaissance (whoami, net user, hostname, systeminfo, TCP connections, DNS server addresses) alongside internal IP ping sweeps and nslookup queries targeting internal Jordanian government FQDNs (ise-posture.mofagov.gover.local, webmail.gov.jo), confirming prior knowledge of the victim network. Attribution to APT34 rests on maldoc similarities with prior APT34 campaigns (including the same mouse anti-sandbox and ENotif beacon pattern), Jordan government targeting history, and DNS C2 with Base32/Base36 encoding consistent with DNSpionage and prior Mandiant-reported APT34 campaigns.

Detected Targets

TypeDescriptionConfidence
CaseForeign Ministry of Jordan
Foreign Ministry of Jordan has been targeted by APT34 as the main target.
Verified
SectorGovernment Agencies and Services
The targeted organization appears to be a government official from Jordan's foreign ministry.
Verified
RegionJordan
Verified

Extracted IOCs

  • asiaworldremit[.]com
  • joexpediagroup[.]com
  • uber-asia[.]com
  • 26884f872f4fae13da21fa2a24c24e963ee1eb66da47e270246d6d9dc7204c2b
  • e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d
download

Tip: 5 related IOCs (0 IP, 3 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

APT34APT34’s Saitama Agent: Phishing and DNS Tunneling in Jordan

Source: XJunior - June 2022

Detection (five cases): 26884f872f4fae13da21fa2a24c24e963ee1eb66da47e270246d6d9dc7204c2b, e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

APT34Understanding Saitama: The Latest Weapon in APT34's Cyber Arsenal

Source: SANS - June 2022

Detection (four cases): e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

APT34APT34 Uses Saitama Backdoor to Attack Jordanian Government through DNS Tunnelling

Source: Malwarebytes - May 2022

Detection (five cases): 26884f872f4fae13da21fa2a24c24e963ee1eb66da47e270246d6d9dc7204c2b, e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

APT34Unveiling APT34’s Advanced Attack Tactics: From Excel Macros to DNS Tunneling

Source: Fortinet - May 2022

Detection (four cases): e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: APT34's Saitama Backdoor — Discovery Report

On April 26, 2022, Malwarebytes discovered a spearphishing email targeting a government official at Jordan's Foreign Ministry. The email came from a Microsoft Outlook account impersonating a Jordanian government contact, using the national coat of arms as a signature. The Excel attachment contained a macro that installed a new backdoor called Saitama — written by APT34, an Iranian state-aligned threat group. What made the discovery particularly significant was finding internal Jordanian government IP addresses and internal domain names hardcoded into the malware, proving the attackers had prior knowledge of the victim's network infrastructure.

The attack is attributed to APT34, also known as OilRig, COBALT GYPSY, or HELIX KITTEN — an Iranian threat group active since at least 2014. Malwarebytes bases the attribution on three factors: the maldoc shares behavioral patterns with prior APT34 campaigns (same anti-sandbox technique, same ENotif beaconing pattern documented by Check Point); Jordan's government is a known APT34 target; and Saitama's DNS C2 with Base32/Base36 encoding matches APT34 tools documented by Mandiant and Cisco Talos, including DNSpionage.

The goal is espionage. Saitama gives APT34 persistent, covert access to a compromised government machine — allowing remote command execution and data exfiltration over DNS. The hardcoded internal network commands suggest the attackers planned to conduct reconnaissance of Jordan's Foreign Ministry network before extracting sensitive information. APT34 is known to focus on government, financial, energy, chemical, and telecommunications sectors across the Middle East.

The attack targeted a specific government official at Jordan's Foreign Ministry — a single, high-value individual selected through prior reconnaissance. The hardcoded internal IP addresses and internal domain names in Saitama's command list confirm the attacker performed detailed pre-attack research on the target network before deploying the malware. This was not a mass campaign — it was a precision operation against a single diplomatic target.

The confirmed target was Jordan's Foreign Ministry — specifically a government official in the diplomatic sector. APT34 is documented to have targeted Jordan's government in prior campaigns. Jordan's diplomatic role in the Middle East and its relationships with Western and Gulf partners make its Foreign Ministry a persistent intelligence target for Iranian state interests.

The victim received a spearphishing email impersonating a Jordanian government official. Opening the Excel attachment and enabling the macro triggered a chain of events: the macro first beaconed its execution steps to the C2 using Windows Management Instrumentation (a system administration tool) rather than direct DNS calls — an unusual evasion technique. It checked for a connected mouse before proceeding (an anti-sandbox measure), then wrote three payload files to disk and set up a scheduled task called "MicrosoftUpdate" to run the Saitama backdoor every time the machine started. Saitama then communicated with APT34's servers exclusively over DNS, cycling through states of waiting, requesting commands, executing them, and sending results back — with sleep periods of up to 6–8 hours between failed connection attempts to avoid detection.

Jordan's Foreign Ministry handles diplomatic communications of direct value to Iranian intelligence — including relations with Israel, the US, Saudi Arabia, and other Gulf states. APT34 has a documented history of targeting Jordan's government. The presence of hardcoded internal network addresses in Saitama suggests the attackers already had some level of knowledge about the ministry's infrastructure before this specific attack, implying an ongoing intelligence interest rather than opportunistic targeting.

Block the three C2 domains (uber-asia[.]com, asiaworldremit[.]com, joexpediagroup[.]com) and hunt for the malware using the published SHA256 hashes. Alert on WMI Win32_PingStatus queries initiated by Office application processes — this is an unusual and specific indicator of Saitama's C2 beaconing. Monitor for new scheduled tasks named "MicrosoftUpdate" and files written to %APPDATA%/MicrosoftUpdate from Office parent processes. Because Saitama specifically checks for a connected mouse to defeat sandbox analysis, automated scanning alone may not detect it — live endpoint monitoring with EDR tools is more reliable. Disable Office macros via Group Policy and sandbox all email attachments before delivery.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights