logo

metador_An_Unattributed_Threat_Hiding_in_Telcos_SPs_and_Universities.pdf

ID: df4696b1-1f77-4c5a-b427-aefa91265ae5

STIX ID: report--df4696b1-1f77-4c5a-b427-aefa91265ae5

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2022-09-22

Last Modified Date: 2022-09-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary: SentinelLabs describes a previously undocumented advanced threat actor named "Metador" that targets telcos, ISPs, and universities in the Middle East and Africa using in-memory Windows implants (metaMain and Mafalda), port-knocking/forwarding infrastructure (Cryshell), and sophisticated anti-analysis techniques; the report includes technical execution flows, 60+ Mafalda commands, IOCs (file hashes, C2 IPs/domains), and limited attribution indicators suggesting multilingual developers and contractor-style operations.