Threats Feed|Nazar|Last Updated 18/06/2026|AuthorCertfa Radar|Publish Date23/04/2020

The Espionage Arsenal of Nazar's Backdoor

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Keylogger,Malware,Spyware
  • Attack Complexity: Medium
  • Threat Risk: Unknown

Threat Overview

The Nazar APT's backdoor, showcases a suite of espionage tools used for malicious activities. It employs a passive approach, utilizing the discontinued Packet Sniffer SDK (PSSDK) for communication. Key capabilities include a keylogger that saves data in %WINSYSDIR%\report.txt, system shutdown through an OLE object, screen capture saved in %CWD%\z.png, audio recording saved as %WINSYSDIR%\music.mp3, and enumeration of drives, files, and installed programs with results stored in %WINSYSDIR%. Additionally, it can remove files, list devices, perform a ping operation, and gather OS information. This malware is specifically designed for espionage, indicating a focus on data extraction and system information discovery.

Extracted IOCs

  • 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
download

Tip: 1 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.

Overlaps

NazarExploring Nazar: A Cyber Campaign Reliant on Open-Source Libraries

Source: Checkpoint - May 2020

Detection (one case): 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6

NazarNazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors

Source: Epicturla - April 2020

Detection (one case): 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Nazar APT and EYService Backdoor

Cybersecurity researchers recently analyzed a piece of malicious software to understand exactly how it operates. They successfully decoded the specific commands the malware uses, revealing a hidden toolkit designed to quietly spy on and manipulate infected computers.

The malware belongs to a highly capable hacking group known as the Nazar APT. The specific tools used by this group were originally uncovered during a massive 2017 leak of cyber espionage materials, linking them to sophisticated, global hacking operations.

The primary goal of this malware is stealthy surveillance and data theft. The program acts as a hidden backdoor, allowing attackers to secretly record audio, capture screenshots, log what a user types, and create a complete inventory of the files and software on the infected machine.

The provided report focuses on the technical capabilities of the malware rather than identifying specific victims. However, tools of this sophistication are typically deployed by advanced groups to target high-value organizations for espionage purposes.

Attackers planted a hidden "backdoor" program on victim computers that passively listens for remote commands. Once commanded, it uses a series of hidden files to activate the computer's microphone, take pictures of the screen, and record keystrokes, saving all this data into hidden text, audio, and image files to be stolen later.

Groups using deep surveillance tools like this are typically looking to steal sensitive communications, trade secrets, or strategic internal data. Any organization or individual that holds valuable, confidential information would be an attractive target for this type of intelligence-gathering operation.

Organizations should update their security systems to hunt for the specific files and network behaviors associated with this threat. Because the malware uses an outdated piece of software to sniff network traffic, organizations can configure their defenses to flag that specific, unusual network activity.

This appears to be a highly targeted threat rather than a widespread issue affecting everyday consumers. The use of specialized, stealthy tools tied to an advanced persistent threat (APT) group indicates focused espionage campaigns against specific, chosen targets.

About Affiliation
Nazar
Nazar is an Iranian-linked threat actor first identified in April 2020 by researcher Juan Andres Guerrero-Saade through analysis of the NSA's "Territorial Dispute" detection signatures leaked by the Shadow Brokers in 2017. Active since at least 2008, the group operated undetected by the security industry for over a decade, with the NSA having monitored it before 2013. All known Nazar subcomponent samples were submitted to VirusTotal from Iran, and Farsi language artifacts found in the malware's debug paths — including the term "khzer" meaning "to survey or monitor" — point to Iranian origin and likely domestic targeting. The group's modular toolkit includes a dropper that registers DLLs as OLE controls, an orchestrator disguised as svchost.exe, and components for screen capture, microphone recording, keylogging, and a passive network packet sniffer that monitors interface traffic for covert command and control. Check Point's subsequent analysis confirmed the toolkit's use of open-source libraries and assessed the code quality as below the standard of sophisticated state espionage groups, suggesting Nazar operated as a lower-tier surveillance capability possibly directed at targets inside Iran.
View Nazar's Insights