UnsolicitedBooker Central Asian telecom phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters because it delivers remote-access backdoors and data-exfiltration capability. The group used Microsoft Office documents with malicious macros to drop loaders that install LuciDoor and MarsSnake. By January 2026, the operation was still active and had adapted to send links to decoy documents instead of attachments. The activity shows a sustained Central Asian targeting pattern rather than a one-off intrusion.
Related Happenings
Microsoft SharePoint remote code execution (CVE-2026-45659)
Vulnerability
H score17
First: 26.05.2026 14:49
Last: 26.05.2026 14:49
Sources 1
About this happening:
Microsoft SharePoint CVE-2026-45659 is a remote code execution vulnerability that lets an authenticated attacker with Site Member permissions run code over the...
Microsoft SharePoint remote code execution (CVE-2026-45659)
VulnerabilityAbout this happening: Microsoft SharePoint CVE-2026-45659 is a remote code execution vulnerability that lets an authenticated attacker with Site Member permissions run code over the...
Webworm expanded European government and South Africa university espionage campaign
Campaign
H score24
First: 20.05.2026 14:30
Last: 20.05.2026 14:30
Sources 1
About this happening:
Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
Webworm expanded European government and South Africa university espionage campaign
CampaignAbout this happening: Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
Ghostwriter geofenced PDF spear-phishing campaign targeting Ukrainian government entities
Campaign
H score50
First: 14.05.2026 17:00
Last: 14.05.2026 17:00
Sources 1
About this happening:
The Ghostwriter / FrostyNeighbor group is running a geofenced spear-phishing campaign against government entities in Ukraine, and the operation matters because it deli...
Ghostwriter geofenced PDF spear-phishing campaign targeting Ukrainian government entities
CampaignAbout this happening: The Ghostwriter / FrostyNeighbor group is running a geofenced spear-phishing campaign against government entities in Ukraine, and the operation matters because it deli...
HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators
Campaign
H score29
First: 11.05.2026 15:00
Last: 11.05.2026 15:00
Sources 1
About this happening:
The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...
HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators
CampaignAbout this happening: The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...
Mongolian governmental institution hit by network compromise
Incident
H score27
First: 23.04.2026 12:04
Last: 23.04.2026 12:04
Sources 1
About this happening:
A Mongolian governmental institution was found to have about 12 systems infected by GopherWhisper backdoors, exposing a live government compromise and the potential fo...
Mongolian governmental institution hit by network compromise
IncidentAbout this happening: A Mongolian governmental institution was found to have about 12 systems infected by GopherWhisper backdoors, exposing a live government compromise and the potential fo...
Timeline
-
24.02.2026 11:54 2 articles · 4mo ago
UnsolicitedBooker shifts to Kyrgyz and Tajik telecom targets
Technical Analysis UpdatePositive Technologies identified UnsolicitedBooker targeting telecommunications companies in Kyrgyzstan and Tajikistan with phishing emails that delivered Microsoft Office documents in late September 2025, then reused the same delivery chain with MarsSnakeLoader in late November 2025 and with link-based decoy documents in January 2026; the campaign used LuciLoad to drop LuciDoor, MarsSnakeLoader to deploy MarsSnake, and represented a shift away from prior Saudi Arabian targets.
Show sources
- UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors — thehackernews.com — 24.02.2026 11:54
- UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors — thehackernews.com — 24.02.2026 11:54