UnsolicitedBooker is a China-aligned threat activity cluster active since at least March 2023. The actor has targeted telecommunications organizations in Kyrgyzstan and Tajikistan and previously targeted entities in Saudi Arabia, with broader activity reported across Asia, Africa, and the Middle East. Reporting has also noted tactical overlaps with the Space Pirates cluster and similarities to tradecraft associated with Mustang Panda, but UnsolicitedBooker is tracked as a distinct cluster. The group commonly gains initial access through phishing emails delivering malicious Microsoft Office documents that prompt victims to enable macros. Those macros deploy loaders including LuciLoad and MarsSnakeLoader, which in turn install the LuciDoor or MarsSnake backdoors. Additional intrusion chains have used Windows shortcut-based lures and script execution to launch malware directly. UnsolicitedBooker’s malware supports system reconnaissance, command execution, file read and write operations, and data exfiltration. LuciDoor and MarsSnake have both been used as backdoors for post-compromise control of victim systems. The actor has also used rare Chinese-origin tooling and, in at least one case, compromised routers as command-and-control infrastructure. Some infrastructure and operational elements have been configured to mimic Russia, indicating an element of deception or false-flag tradecraft. Known malware associated with the cluster includes LuciDoor, MarsSnake, LuciLoad, and MarsSnakeLoader.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned intrusion cluster conducting espionage-style intrusions, shifting targeting from Saudi Arabian entities to telecommunications providers in Kyrgyzstan and Tajikistan; uses phishing with malicious Office documents and macro-enabled loaders to deploy LuciDoor and MarsSnake backdoors for system discovery, command execution, and data exfiltration; has used compromised routers for C2 and tooling overlaps with other clusters.
China-aligned espionage activity cluster conducting phishing-led intrusions (malicious Office docs/macros and LNK-based execution chains) to deploy custom backdoors (LuciDoor, MarsSnake) against telecom and other organizations; observed shifting targeting from Saudi Arabia to Kyrgyzstan/Tajikistan, with some indications of MarsSnake used in attacks targeting China.
ESET-tracked Chinese-linked APT referenced as potentially related to a campaign targeting telecoms in Kyrgyzstan and Tajikistan using LuciDoor and MarsSnake backdoors.
China-aligned actor conducting multi-year intrusion against an organization in Saudi Arabia; used spear-phishing and deployed MarsSnake backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.