Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-Chafer-creat4491-en_EN:Bitdefender-PR-Whitepaper-Chafer-creat4491-en_EN.indd
ID: 8592e3ec-15cc-4281-ae1d-a138ea94a0ea
STIX ID: report--8592e3ec-15cc-4281-ae1d-a138ea94a0ea
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2020-05-15
Last Modified Date: 2020-05-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender documents Iranian-linked Chafer APT campaigns (2018–2019) targeting air transport and government entities in Kuwait and Saudi Arabia, describing initial compromise methods (likely spearphishing/tainted documents or social engineering), lateral movement using PSExec/RDP, persistent backdoors (modified Plink, custom RATs, Remexi), proxy/tunneling tools, credential dumping (Mimikatz), scheduled-task/service persistence, and evidence of data exploration/exfiltration; the report includes timelines, detailed tool analyses, MITRE mappings, and IoCs (SHA256 hashes and malicious domains).
