Threats Feed|Nazar|Last Updated 29/06/2026|AuthorCertfa Radar|Publish Date22/04/2020

Nazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper,Keylogger,Malware,Spyware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Nazar APT, active since at least 2010, employs a modular toolkit for cyber espionage. Its main dropper registers multiple DLLs as OLE controls in the Windows registry using 'regsvr32.exe'. It includes a service disguised as 'svchost.exe' for persistence, and uses custom and repurposed libraries for various functionalities like keylogging, audio capture, and screen capture. Nazar's droppers, built with Chilkat's 'Zip2Secure', are often misidentified by antivirus software. A notable feature is EYService, a passive backdoor listening on UDP port '1234', enabling commands like ping response, victim info requests, and file downloads. Additionally, it uses a packet sniffer for potentially sophisticated command-and-control activities. The report, however, does not specify targeted countries or sectors.

Detected Targets

TypeDescriptionConfidence
RegionIran
Verified

Extracted IOCs

  • 6b3116580d29020b9c259877ac18a7fd
  • a9ff31c8db6d4e70829bf5db062d1b9c
  • c1ab32afb0e2d7b7b1cad3fb831e9373
  • 05122010cde4dcd1b4cd55de7b7d442efda19976
  • 48f99144bb9fdf379926e85fbe3caa462089f397
  • 79f2b98821c1e2717a0495e6c5c76a0147b21aae
  • 0091e2101f00751c4020ef8e115cfe12a284c9abacc886f549b40a62574a7510
  • 048208864c793a670159723b38c3ea1474ccc62e06b90833bdf1683b8026e12f
  • 0c09fedc5c74f90883cd3256a181d03e4376d13676c1fe266dbd04778a929198
  • 1110c3e34b6bbaadc5082fabbdd69f492f3b1480724b879a3df0035ff487fd6f
  • 1c02043ca00d087f1aac0337f89bf205985e1f20641bf043c9b7b99e0c9dc002
  • 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
  • 4d0ab3951df93589a874192569cac88f7107f595600e274f52e2b75f68593bca
  • 5a924dec60c623cf73f5b8505e11512ad85e62ac571a840ab0ff48d4a04b60de
  • 6b8ea9a156d495ec089710710ce3f4b1e19251c1d0e5b2c21bbeeab05e7b331f
  • 75e4d73252c753cd8e177820eb261cd72fecd7360cc8ec3feeab7bd129c01ff6
  • 839c3e6ba65e5d07a2e0c4dd4a2c0d7ae95a266431dd3f8971b8a37d17b1ddf6
  • 8fb9a22b20a338d90c7ceb9424d079a61ca7ccb7f78ffb7d74d2f403ae9fbeec
  • 967ac245e8429e3b725463a5c4c42fbdf98385ee6f25254e48b9492df21f2d0b
  • c84100d52c09703e32951444bd7ba4e22c5d41193e7420aacbbc1f736f4c4e1f
  • d34a996826ea5a028f5b4713c797247913f036ca0063cc4c18d8b04736fa0b65
  • d9801b4da1dbc5264e83029abb93e800d3c9971c650ecc2df5f85bcc10c7bd61
  • eb705459c2b37fba5747c73ce4870497aa1d4de22c97aaea4af38cdc899b51d3
download

Tip: 23 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 23 file hash) to this threat have been found.

Overlaps

NazarExploring Nazar: A Cyber Campaign Reliant on Open-Source Libraries

Source: Checkpoint - May 2020

Detection (16 cases): 0091e2101f00751c4020ef8e115cfe12a284c9abacc886f549b40a62574a7510, 048208864c793a670159723b38c3ea1474ccc62e06b90833bdf1683b8026e12f, 0c09fedc5c74f90883cd3256a181d03e4376d13676c1fe266dbd04778a929198, 1110c3e34b6bbaadc5082fabbdd69f492f3b1480724b879a3df0035ff487fd6f, 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6, 4d0ab3951df93589a874192569cac88f7107f595600e274f52e2b75f68593bca, 5a924dec60c623cf73f5b8505e11512ad85e62ac571a840ab0ff48d4a04b60de, 6b8ea9a156d495ec089710710ce3f4b1e19251c1d0e5b2c21bbeeab05e7b331f, 75e4d73252c753cd8e177820eb261cd72fecd7360cc8ec3feeab7bd129c01ff6, 839c3e6ba65e5d07a2e0c4dd4a2c0d7ae95a266431dd3f8971b8a37d17b1ddf6, 8fb9a22b20a338d90c7ceb9424d079a61ca7ccb7f78ffb7d74d2f403ae9fbeec, 967ac245e8429e3b725463a5c4c42fbdf98385ee6f25254e48b9492df21f2d0b, c84100d52c09703e32951444bd7ba4e22c5d41193e7420aacbbc1f736f4c4e1f, d34a996826ea5a028f5b4713c797247913f036ca0063cc4c18d8b04736fa0b65, d9801b4da1dbc5264e83029abb93e800d3c9971c650ecc2df5f85bcc10c7bd61, eb705459c2b37fba5747c73ce4870497aa1d4de22c97aaea4af38cdc899b51d3

NazarThe Espionage Arsenal of Nazar's Backdoor

Source: Malwarelab - April 2020

Detection (one case): 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Demystifying the Nazar Threat

Cybersecurity researchers uncovered a previously unknown cyber espionage campaign from over a decade ago. By re-examining leaked documents from a group known as ShadowBrokers, researchers found a mislabeled file signature that led them to discover a hidden surveillance toolkit.

The exact identity of the attackers is unconfirmed, but researchers named the group "Nazar." Evidence, such as Farsi language artifacts and specific file paths found in the code, suggests the group is Farsi-speaking, potentially operating an internal monitoring operation.

The primary goal of the attack was covert espionage and surveillance. The malicious toolkit was specifically designed to secretly record audio via microphones, take screenshots, log user keystrokes, and monitor network traffic.

The scope of this campaign was highly targeted rather than a mass-infection event. Historical data shows that the infections were clustered almost entirely on specific machines located in Iran.

While the report does not name specific industries, the victims were highly targeted individuals or systems within Iran. These same systems were also being monitored by foreign intelligence agencies, indicating the victims held significant strategic or political value.

Attackers used setup files designed to look like routine updates to drop various surveillance tools onto a victim's computer. These tools then hid themselves by mimicking normal Windows systems and quietly listened for remote commands over the network to steal information.

The targeted entities were attractive because they likely possessed highly sensitive intelligence. The fact that these same computers were targeted by multiple sophisticated intelligence groups highlights their high-value status.

Organizations should ensure their security systems are actively monitoring for unauthorized software services and silent file modifications. Network defenders should also look for unusual network traffic, especially services silently listening for commands on unexpected ports like UDP 1234.

This was a highly targeted, localized issue and does not represent a widespread threat to the general public. It is an older, specialized intelligence-gathering campaign rather than modern, widespread malware like ransomware.

About Affiliation
Nazar
Nazar is an Iranian-linked threat actor first identified in April 2020 by researcher Juan Andres Guerrero-Saade through analysis of the NSA's "Territorial Dispute" detection signatures leaked by the Shadow Brokers in 2017. Active since at least 2008, the group operated undetected by the security industry for over a decade, with the NSA having monitored it before 2013. All known Nazar subcomponent samples were submitted to VirusTotal from Iran, and Farsi language artifacts found in the malware's debug paths — including the term "khzer" meaning "to survey or monitor" — point to Iranian origin and likely domestic targeting. The group's modular toolkit includes a dropper that registers DLLs as OLE controls, an orchestrator disguised as svchost.exe, and components for screen capture, microphone recording, keylogging, and a passive network packet sniffer that monitors interface traffic for covert command and control. Check Point's subsequent analysis confirmed the toolkit's use of open-source libraries and assessed the code quality as below the standard of sophisticated state espionage groups, suggesting Nazar operated as a lower-tier surveillance capability possibly directed at targets inside Iran.
View Nazar's Insights