Threats Feed|APT34|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date02/03/2020

APT34 Strikes Lebanese Government with MailDropper Implant

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Telsy's threat intelligence team provides the most detailed technical analysis of the MailDropper implant used by APT34 against Lebanese government entities in early 2020, published simultaneously with Yoroi's parallel report on the same sample. The infection begins with a spearphishing Excel document containing a VBA macro that drops monitor.exe into a hidden .Monitor folder under C:\Users\Public\. A scheduled task named "SystemErrorReporter" runs the payload every minute. The monitor.exe binary contains hardcoded credentials for a compromised Exchange account (redacted as media@xxx.local) belonging to the targeted Lebanese government institution. Commands are retrieved by polling the Exchange Inbox for emails with the subject "Resume7AKF1PMAVAHI7SYK"; matching emails have Base64-encoded command payloads in their attachments, which are extracted and executed via ExecAllCmds. After processing, each email is permanently deleted with the HardDelete flag — ensuring processed commands leave no trace in the trash folder. Results are returned as new emails with subject "Great! 7AKF1PMAVAHI7SYK" + date, body "This is our reusme!" (syntax error preserved as a forensic indicator), with command output base64-encoded in an attachment named resume.txt. If the Exchange server is unavailable, MailDropper falls back to a backup HTTP C2 at godoycrus[.]com. All data exchanged with the C2 is encrypted using AES+RSA hybrid encryption: data is AES-encrypted with an auto-generated key, the key is then RSA-encrypted and prepended to the payload. Telsy draws four specific parallels to DNSpionage (Lebanon targeting, Excel macro delivery, dot-prefixed hidden folder, .NET payload) as supporting attribution to APT34. Telemetry at time of publication confirmed the implant was in use exclusively within Lebanon.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionLebanon
Verified

Extracted IOCs

  • godoycrus[.]com
  • b08dff2a95426a0e32731ef337eab542
  • c53d785917c1da4d40cd9fac1455d096faa4b672
  • ebae23be2e24139245cc32ceda4b05c77ba393442482109cc69a6cecc6ad1393
download

Tip: 4 related IOCs (0 IP, 1 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.

Overlaps

APT34APT34 Strikes Again: Government Sector in Lebanon Under Karkoff Attack

Source: Yoroi - March 2020

Detection (two cases): ebae23be2e24139245cc32ceda4b05c77ba393442482109cc69a6cecc6ad1393, godoycrus[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: APT34's MailDropper Implant Against Lebanon's Government

Telsy discovered a custom APT34 implant called MailDropper being used against Lebanese government entities in early 2020. The malware was delivered via a spearphishing Excel document and, once installed, communicated with attackers entirely through a compromised Lebanon government Exchange email server — disguising all malicious activity as ordinary email traffic. Telsy's report provides the deepest technical detail of the campaign, including the exact email subject patterns used for command delivery and result exfiltration, and confirms the malware was in use exclusively in Lebanon at time of publication.

The attack is attributed to APT34, also known as OilRig or Helix Kitten — an Iranian state-linked cyberespionage group active since at least 2014. Telsy identifies four specific similarities between MailDropper and APT34's prior DNSpionage tool: both targeted Lebanon, both used Excel macro delivery, both used a dot-prefixed hidden folder for the payload, and both used .NET-compiled payloads. Yoroi's parallel analysis of the same sample reaches the same attribution conclusion.

The campaign was focused on espionage and data collection from Lebanese government targets. MailDropper can execute arbitrary commands, transfer files, and exfiltrate data — all communicated through legitimate encrypted Exchange email traffic. Telsy notes APT34 likely exploited trust between the initially compromised institution and other Lebanese government entities to extend the operation's reach, using the compromised Exchange server as a bridge into multiple targets.

Telsy's telemetry confirmed the implant was in use exclusively within Lebanon at time of publication, confirming its narrowly targeted nature. The hardcoded Exchange credentials inside the binary suggest APT34 had already compromised a specific Lebanese government Exchange account before deploying MailDropper, indicating pre-operational access and a deliberate, patient targeting process rather than opportunistic infection.

All known victims were Lebanese government entities. APT34 has consistently targeted Lebanon's government since at least 2018, running successive campaigns (DNSEspionage, Karkoff, MailDropper/Karkoff 2020) against the same target base. The use of a government-owned Exchange server as C2 and the exploitation of trust between institutions suggests the group maintains persistent operations against Lebanon rather than conducting isolated attacks.

A spearphishing email delivered a macro-armed Excel file to the target. The macro dropped monitor.exe into a hidden folder (C:\Users\Public\.Monitor\) and set it to run every minute via a scheduled task. The implant read hardcoded Exchange credentials from within its own binary, connected to the compromised government Exchange server, and looked for emails with the subject "Resume7AKF1PMAVAHI7SYK." Commands were base64-encoded in email attachments; once executed, results were sent back as a new email with a matching subject containing the date, with command output encoded in a resume.txt attachment. Each processed email was permanently deleted with the HardDelete flag. All traffic between the malware and the Exchange server was encrypted with AES+RSA.

Lebanon's government is a persistent target for Iranian intelligence. Hezbollah's role in Lebanese politics, Lebanon's diplomatic relationships with Western powers and Gulf states, and the country's position as a regional information hub all make Lebanese government communications strategically valuable to Iranian state interests. APT34's repeated use of the same target base over multiple years reflects standing intelligence-collection requirements against Lebanon rather than one-time opportunistic targeting.

Audit Exchange inbox access logs for automated polling of emails with subject "Resume7AKF1PMAVAHI7SYK" — this is a direct behavioral indicator of an active MailDropper infection. Monitor Exchange audit logs for HardDelete operations on unusual subject patterns and for automated email send activity matching "Great! 7AKF1PMAVAHI7SYK" subjects. Hunt for monitor.exe in C:\Users\Public\.Monitor\ and scheduled tasks named "SystemErrorReporter." Block godoycrus[.]com — the backup C2 — and scan endpoints using the published file hashes. Enforce MFA on all Exchange accounts to prevent credential-based compromise, which is how APT34 obtained the hardcoded Exchange access used by MailDropper.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights