logo

Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-Chafer-creat4491-en_EN:Bitdefender-PR-Whitepaper-Chafer-creat4491-en_EN.indd

ID: 8592e3ec-15cc-4281-ae1d-a138ea94a0ea

STIX ID: report--8592e3ec-15cc-4281-ae1d-a138ea94a0ea

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-05-15

Last Modified Date: 2020-05-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender documents Iranian-linked Chafer APT campaigns (2018–2019) targeting air transport and government entities in Kuwait and Saudi Arabia, describing initial compromise methods (likely spearphishing/tainted documents or social engineering), lateral movement using PSExec/RDP, persistent backdoors (modified Plink, custom RATs, Remexi), proxy/tunneling tools, credential dumping (Mimikatz), scheduled-task/service persistence, and evidence of data exploration/exfiltration; the report includes timelines, detailed tool analyses, MITRE mappings, and IoCs (SHA256 hashes and malicious domains).