#ArabianNight
Incident/Operation
2017-05-12 • OPERATION ‘Arabian Night'
ArabianNight was a targeted campaign documented in 2017 that used malicious Microsoft Word files and VBA macros to install a backdoor on Windows systems. The operation was linked through code and tradecraft to earlier attacks against South Korean organizations and to malware associated with the Sony Pictures intrusion, while later related activity used cryptocurrency-themed job descriptions against targets in Vietnam. Distinguishing features included embedded executables decoded with XOR, command strings assembled in macros, process injection, remote-control functionality, and tailored spear-phishing documents.
-
2
Tagged Reports
-
1
Unique Authors
-
265
Active Days