Unattributed — low confidence on sponsor (Arabic-speaking operators)
Origin
Unknown
First seen
2022
Last active
2023
Motivation
Espionage
Attribution confidence
medium
MENA targeting
Middle East and North Africa (broad, Arabic-speaking targets)
Sectors
General/opportunistic, cross-sector via geopolitical lures
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Middle East and North Africa (broad, Arabic-speaking targets) (General/opportunistic, cross-sector via geopolitical lures sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
NjRAT allows attackers to conduct a myriad of intrusive activities on infected systems such as stealing sensitive information, process/registry/file manipulation, and uploading/downloading files.
The malicious file is hidden inside a Microsoft Cabinet (CAB) archive file masquerading as a 'sensitive' audio file, named using a geopolitical theme as a lure to entice victims to open it.
The PowerShell script loads Payload_1 and Payload_2 into memory and injects NjRAT into aspnet_compiler.exe; the script 'KxFXQGVBtB.ps1' executes 'aspnet_compiler.exe' in conjunction with the process injector to inject NjRAT.
NjRAT provides attackers a reverse shell for interactive command execution on infected systems, among its other capabilities (registry and file manipulation, upload/download of files).
The malicious CAB file contains an obfuscated VBS (Visual Basic Script) dropper responsible for delivering the next stage of the attack; once downloaded, the obfuscated VBS script runs to fetch the malware from a compromised or spoofed host.
The VBS script retrieves a PowerShell script responsible for injecting NjRAT into the compromised victim's machine; the second-stage dropper is an obfuscated PowerShell script that drops five files in total: two binaries, a VBS script, a PowerShell script, and a Windows batch script.
Distribution mechanism could be via social media (Facebook and Discord appear to be favored), file sharing (OneDrive), or a phishing email, all using Middle Eastern geopolitical-themed lures.
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
persistence
The dropper achieves persistence on an infected system by adding the directory C:\ProgramData\WindowsHost to the 'User Shell' folders and 'Shell' folders startup keys accordingly.
The threat actor uses public cloud storage services such as files.fm and failiem.lv to host malware, while compromised web servers distribute NjRAT.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Earth Bogle's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 8 techniques
Advanced Anti-Phishing T1566partialAnti-SpoofingT1566significantDefender for Cloud AppsT1119partialMultifactor AuthenticationT1566partialRole Based Access ControlT1059minimalAntimalwareT1027significantAntimalwareT1036significantAntimalwareT1059significantAntimalwareT1059.001significantAntimalwareT1204significantAntimalwareT1204.002significantAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantInformation ProtectionT1119significant
detect · 7 techniques
Adaptive Application Control IntegrationT1036partialAdaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialApp GovernanceT1566significantAdvanced Threat HuntingT1566significantDefender for Cloud AppsT1119partialMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1059.001minimalPreset Security PoliciesT1204significantPreset Security PoliciesT1566significantSafe AttachmentsT1204significantSafe AttachmentsT1204.002significant
respond · 7 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1036significantQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantQuarantine PoliciesT1566significantSafe AttachmentsT1204significantSafe AttachmentsT1204.002significantSafe AttachmentsT1566significantATT&CK Simulation Training
Countermeasures · D3FEND
Defensive techniques that counter Earth Bogle's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.