Iranian Chafer APT Targets Kuwait and Saudi Arabia’s Critical Sectors
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Credential stuffing,Backdoor,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Bitdefender's May 2020 whitepaper documents two Chafer APT campaigns dating to 2018 against air transportation and government targets in Kuwait and Saudi Arabia. The Kuwait attack was the more sophisticated of the two. Initial access was likely achieved via spearphishing with shellcode-laden documents executing Metasploit reverse TCP payloads. Attackers then deployed a full toolkit: CrackMapExec for network scanning, credential dumping, and account enumeration; Mimikatz (including a SafetyKatz variant and a customized version) for credential dumping; a modified Plink (wehsvc.exe) installed as a Windows service for C2 and tunneling; custom proxy tools (mini.exe, mfevtpse.exe) using SOCKS5 over HTTP disguised with bing.com host headers; and custom Python-based RATs (snmp.exe/imjpuexa.exe) using DNS and HTTP C2 channels that marshal packets to resemble legitimate DNS/HTTP traffic. A MechaFlounder-variant RAT (drivers.exe/dbxservice.exe) established persistence via scheduled tasks ("Defender Update" / "Service Update") and exfiltrated data to Dropbox — each victim had a separate folder named by machine+username combination. The RTLO character (U+202E) was used in filenames to spoof file extensions for defense evasion. Attackers created their own user accounts on compromised machines and operated primarily on weekends (Friday/Saturday — the regional weekend), suggesting awareness of Middle Eastern business hours. Scanning tools included a modified nbtscan variant (xnet.exe) and etblscanner.exe, an EternalBlue scanner written in Python. Shared PDB paths and compiler artifacts link xnet.exe to Remexi (mas.dll), connecting this campaign to prior Chafer infrastructure. The Saudi Arabia attack was simpler: social engineering led a user to execute a RAT directly from their Downloads folder (parent process: explorer.exe), suggesting the user was tricked into double-clicking a malicious file.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Sector | Aerospace | Verified |
| Region | Kuwait | Verified |
| Region | Saudi Arabia | Verified |
Extracted IOCs
- apigoogle-accounts[.]biz
- dropboxengine[.]com
- redjewelry[.]biz
- update-microsoft[.]space
- 021813c78cf31b0d7e77b40374347d8ed4e5a5ca69a7fc29bbc7bff969c09f3c
- 11dbfb390f7008524e523da7d0cda61723584082fc91ff96d1148c4aac6198a0
- 144a160c57c2d429d072046edfdd1b44ff22bcae4f0535732f6c2b19190f2f35
- 508ba7971b1f7651ba7d26815f75d66977820bd4eb3a615e3ab7079058d80380
- 5ee9873c3c8684ac097bd28d3caf4264c6da6aa6acfeb8f6e72f1a99215a4be8
- 710e32af0d41a6701d57337701b091b158add04a601b68cca67a808bdd87d881
- 98a9b2329eefe618daa78b6afed82cebf40cb918ad0aae7a8d7f59af4cb13b41
- a1f5c72721f9aa2ca29f1de7645a64b505c05dcd53dbdd7b9e904b1627c6d578
- b297a0b2e775f096d9ebda6130abbb5ec59813c7703159ea191b47d7b7293e1e
- c839e886b98d2c752a134e888dad40799cd9966f8a73b51edc85ca2d72f99616
- d965352c6632e694b8f1f62f96874bd0df8d7c128c465ee9a76eb86ebddb0c02
- f991cadf11c5075f0ed6f381dfdac311cf59480962debf8b874f95e9bee5c4f2
Tip: 16 related IOCs (0 IP, 4 domain, 0 URL, 0 email, 12 file hash) to this threat have been found.
Overlaps
Source: Symantec - December 2015
Detection (one case): 98a9b2329eefe618daa78b6afed82cebf40cb918ad0aae7a8d7f59af4cb13b41
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions about Chafer APT's Campaigns in Kuwait and Saudi Arabia
Bitdefender researchers documented two Chafer APT campaigns from 2018 targeting air transportation and government organizations in Kuwait and Saudi Arabia. The Kuwait operation was elaborate and lasted more than 18 months — attackers gained initial access, moved laterally across the network, created their own user accounts, and prepared for data exfiltration using tools including a custom RAT that communicated via Dropbox. The Saudi Arabia attack was simpler, with a user tricked into executing a malicious file directly. Both campaigns were attributed to Chafer APT, an Iranian-linked threat group active since 2014.
Chafer APT is an Iranian-linked cyberespionage group active since at least 2014. The group focuses on intelligence gathering against targets in the Middle East, particularly governments and critical infrastructure. Attribution is supported by tool overlaps with prior documented Chafer campaigns — shared PDB paths and compiler metadata link tools from these attacks to Remexi (mas.dll), a known Chafer backdoor previously documented by Symantec. The group's targeting of air transportation and government sectors in Kuwait and Saudi Arabia is consistent with Iranian state intelligence priorities in the region.
The primary goals were intelligence gathering and data exfiltration. In Kuwait, the attackers deployed Navicat Premium (a database management tool), SmartFTP Password Decryptor, and WinSCP — all tools consistent with exploring and extracting data from compromised systems. A custom RAT that exfiltrated files to Dropbox was also deployed. The attackers were thorough and patient, spending over 18 months inside the Kuwaiti network. The lack of conclusive network logs made it difficult to confirm exactly what data was taken, but the tool selection strongly indicates data exploration and exfiltration were the end goals.
Bitdefender identified victims in two countries: Kuwait (air transportation sector) and Saudi Arabia (government sector). The Kuwait operation was significantly more sophisticated and lasted more than 18 months. The Saudi Arabia attack appeared to be a simpler, more opportunistic operation — possibly abandoned when the attackers found no further exploitable machines after the initial compromise. The specific organizations were not named in the report, but both fit Chafer's established pattern of targeting critical infrastructure and government bodies in the Gulf region.
Air transportation and government organizations in Kuwait and Saudi Arabia were the confirmed targets. Air transportation is attractive because it controls critical national and regional logistics infrastructure, flight data, and communications — all valuable to an intelligence actor monitoring the movement of people and cargo across the Gulf. Government organizations hold sensitive policy and diplomatic communications. Both sectors represent high-value targets for Iranian intelligence collection given ongoing regional geopolitical tensions between Iran, Kuwait, and Saudi Arabia.
The Kuwait attack used a multi-stage chain. Initial access was likely via spearphishing with shellcode-laden documents running Metasploit reverse TCP payloads. From there, the attackers deployed CrackMapExec and Mimikatz variants to harvest credentials, then moved laterally using PsExec and RDP. They installed a modified Plink as a Windows service for tunneling and deployed custom proxy tools using SOCKS5 over HTTP to communicate with C2 servers. Python-based RATs used DNS and HTTP channels that disguised traffic to look like legitimate requests. A MechaFlounder-variant RAT communicated via Dropbox — each victim machine got its own Dropbox folder for receiving commands and uploading stolen files. The attackers created their own user accounts and operated almost exclusively on Fridays and Saturdays, avoiding detection during business hours. The Saudi Arabia attack was much simpler: a user was tricked into double-clicking a malicious file from their Downloads folder — the RAT executed twice within three minutes under the parent process explorer.exe, confirming it was user-initiated.
Gulf state air transportation and government organizations hold intelligence that directly serves Iranian state interests. Kuwait and Saudi Arabia are both regional rivals of Iran and host US and allied military assets — their government communications and infrastructure data are high-value collection targets. Air transportation data specifically reveals the movement of people, cargo, and logistics across the region, which has both military and economic intelligence value. The 18-month dwell time in the Kuwait network indicates the attackers were not in a hurry — they were systematically exploring and mapping the organization's data before exfiltrating.
Patch EternalBlue (MS17-010) on all Windows systems immediately if not already done — etblscanner.exe confirms Chafer was scanning for this vulnerability to exploit for lateral movement. Monitor and restrict RDP access, and alert on rdpwinst.exe enabling multiple concurrent sessions. Detect RTLO characters in filenames at the email gateway to stop extension-spoofed executables. Watch for scheduled tasks named "Defender Update" or "Service Update" — both are Chafer persistence signatures. Monitor outbound Dropbox API traffic from endpoints not provisioned for cloud storage. Block the known C2 domains: dropboxengine[.]com, redjewelry[.]biz, apigoogle-accounts[.]biz, update-microsoft[.]space. Alert on new local user account creation, especially accounts that immediately deploy files to %WINDOWS%\ime or similar unusual system paths. Train employees not to execute files downloaded from email or the web without first verifying with IT — the Saudi Arabia attack succeeded because a user double-clicked a malicious file from their Downloads folder.