Kasablanka is a threat actor tracked in connection with LodaRAT activity and Android surveillance tooling. The group is assessed to be based in Morocco and has been linked to targeted espionage-oriented campaigns in Bangladesh, with earlier activity associated with Latin America and Android operations also linked to the Middle East. Reporting has characterized some of its operations as potentially consistent with a hacker-for-hire or cyber-mercenary model, although that assessment is not conclusive. Kasablanka is associated with both Windows and Android malware use. It has been linked to LodaRAT campaigns that used themed lure websites and social-engineering content tailored to Bangladeshi users, including political, telecom, financial, and public-interest themes, to deliver malware. LodaRAT has been used by the group for information gathering and remote access, including screenshot capture, keylogging, audio recording, command execution, and broader post-compromise surveillance. The actor is also associated with Android malware referred to in some reporting as LodaRAT for Android or LodaRat4Android, and has been linked to use of Android 888 RAT under alternate naming. Android tooling tied to Kasablanka supports extensive device surveillance and data theft, including collection of files, messages, contacts, location data, screenshots, audio, and other sensitive user information. Kasablanka has additionally been observed as a user of the commodity remote access trojan AveMariaRAT, also known as WarZoneRAT. Observed tradecraft across malware associated with Kasablanka includes socially engineered initial access, credential and information theft, keylogging, persistence, process injection, privilege escalation or UAC bypass in the case of AveMariaRAT-linked activity, and broader post-exploitation surveillance. Talos reporting has also noted that Kasablanka should not be treated as the sole operator of LodaRAT, as the malware has appeared in multiple distinct campaigns beyond those attributed to this actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In most of its campaigns, LodaRAT has been spreading through malicious documents, that either contained malicious macros or exploited vulnerabilities in Office. Some earlier campaigns exploited CVE-2017-0199, while more recent ones exploited CVE-2017-11882.
Some earlier campaigns exploited CVE-2017-0199, while more recent ones exploited CVE-2017-11882. Though patched several years ago, the latter vulnerability remains popular among malware authors.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of the threat groups observed using AveMariaRAT/WarZoneRAT.
Referenced as the developer (and sometimes operator) historically attributed with LodaRAT/Loda4Android; the report argues LodaRAT is used by multiple distinct operators and that YoroTrooper’s LodaRAT variants deviate from versions previously associated with Kasablanka.
Threat group linked in the report to use of Android 888 RAT in an organized campaign, referring to the malware as LodaRAT.
An espionage-oriented campaign operator linked to LodaRAT and Loda4Android, using phishing/lure websites and reused infrastructure to target people or entities in Bangladesh. The activity is described as potentially hacker-for-hire or cyber-mercenary in nature.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.