Earth Bogle has targeted victims across the Middle East and North Africa in a malware campaign active since at least mid-2022, using regional geopolitical themes to entice users into opening malicious files. The operation delivers NjRAT (also known as Bladabindi) through malicious CAB archives, obfuscated VBS droppers, and PowerShell-based loaders, with payloads hosted on public cloud storage services including files.fm and failiem.lv and retrieved through compromised or spoofed infrastructure such as gpla[.]gov[.]ly.
Once installed, NjRAT gives the attackers broad remote-access and surveillance capabilities, including information theft, screenshot capture, reverse shell access, file transfer, and registry or process manipulation. The campaign is believed to spread through phishing, file-sharing links, and social platforms such as Facebook and Discord, while persistence is maintained by placing files under C:\ProgramData\WindowsHost and modifying startup-related registry shell folders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Earth Bogle conducted a malware campaign targeting victims across the Middle East and North Africa using geopolitical-themed lure files, malicious CAB archives, VBS droppers, and PowerShell scripts to deliver NjRAT. The activity had been ongoing since at least mid-2022 and likely spread through social media, file-sharing links, and phishing, with Facebook and Discord appearing favored.
The Libyan-affiliated domain gpla[.]gov[.]ly had a history of compromise dating back to at least 2021, before its use in the Earth Bogle activity described in the report.
The domain gpla[.]gov[.]ly, later used in the campaign to retrieve a malicious PowerShell script, was registered in 2019.
The final payload used in the Earth Bogle campaign, NjRAT (also known as Bladabindi), was first discovered in 2013.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.