metador_An_Unattributed_Threat_Hiding_in_Telcos_SPs_and_Universities.pdf
ID: df4696b1-1f77-4c5a-b427-aefa91265ae5
STIX ID: report--df4696b1-1f77-4c5a-b427-aefa91265ae5
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2022-09-22
Last Modified Date: 2022-09-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary: SentinelLabs describes a previously undocumented advanced threat actor named "Metador" that targets telcos, ISPs, and universities in the Middle East and Africa using in-memory Windows implants (metaMain and Mafalda), port-knocking/forwarding infrastructure (Cryshell), and sophisticated anti-analysis techniques; the report includes technical execution flows, 60+ Mafalda commands, IOCs (file hashes, C2 IPs/domains), and limited attribution indicators suggesting multilingual developers and contractor-style operations.
