Spark is a custom Windows backdoor associated with Molerats, also known as Gaza Cybergang, and used in politically motivated cyber-espionage operations. First observed around January 2019, it has targeted Palestinian individuals and organizations through social-engineering campaigns using regional political themes. Delivery chains have used links in lure documents to archives hosted on legitimate cloud-storage services, including Dropbox and Egnyte. These archives contain executables disguised as Microsoft Word documents. AutoIt-based droppers install the backdoor, sometimes display decoy documents, and establish persistence through scheduled tasks and Windows Startup entries.
Spark supports system reconnaissance, identification of the logged-in user, command execution, downloading additional payloads, keylogging, microphone recording, and data exfiltration over its command-and-control channel. It communicates over HTTP and protects transmitted data with encryption and Base64 encoding, including layered transformations around JSON-formatted data. It also uses a custom XOR routine to decrypt its payload. Observed samples employ Enigma Packer and query Windows Management Instrumentation to identify installed antivirus and firewall products. Some variants check keyboard layouts and locale information for Arabic settings and refrain from malicious activity when those settings are absent, restricting execution to the intended target population.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Відправку жертві PDF-документу з посиланням, відвідування якого, у поєднанні з експлуатацією вразливості CVE-2024-38213, призводило до завантаження на комп'ютер LNK-файлу (розширення "pdf.lnk").
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SPARK is listed among the tools used to implement the cyber threat; the indicators identify spark.exe as SPARK and cdnauthsoft[.]com as SPARK-associated infrastructure.
SPARK is listed among the tools used to implement the cyber threat; the indicators identify spark.exe as SPARK and cdnauthsoft[.]com as SPARK-associated infrastructure.
SPARK is listed among the tools used to implement the cyber threat; the indicators identify spark.exe as SPARK and cdnauthsoft[.]com as SPARK-associated infrastructure.
Spark Backdoor: Hashes (SHA-256 + SHA-1) ... Domains Brooksprofessional[.]com IPs 168.119.82.89 93.115.10.142
"The payload in a majority of these attacks was a backdoor called Spark, which is a backdoor that allows the threat actors to open applications and run command line commands on the compromised system."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The extracted executable file contains a compiled Autoit script, which can be seen in the RT_RCDATA section of the file.
They pack the malware with a powerful commercial tool called Enigma Packer ... All the payloads observed by Cybereason in this campaign were packed by ... Enigma Packer.
The executable has a Microsoft Word icon to trick victims into believing they are opening a Word document.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
If Arabic keyboard and language settings are not found on the machine, the backdoor will not carry out its malicious activity ... It can thwart detection by automated analysis engines and sandbox solutions.
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
121 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious tool used in the described supplier-targeting campaigns. The reference supplies a sample hash and associated network infrastructure but does not explain its specific capabilities.
A backdoor/implant used by Gaza Cybergang to maintain persistence on compromised systems for espionage.
Backdoor used in a related campaign targeting Palestinians via social engineering.
A backdoor previously attributed to Molerats and used in conjunction with the newly discovered malware in targeted attacks against Palestinian officials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.