Uptime Hamster: 10d 19h 34mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza MalKamak

MalKamak

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Aliases: APT MALKAMAK, Operation GhostShell, ShellClient, dominios como www
Ver en IntelTracker → APTTrail →
MalKamak is an Iranian cyber espionage group that first emerged in 2018, operating undetected for at least three years. The group primarily conducts cyber espionage, focusing on the theft of sensitive information from targeted entities. MalKamak is notable for the continuous development and use of ShellClient, a custom Remote Access Trojan that evolved from a basic reverse shell into a modular espionage tool, and its unique approach of utilizing legitimate cloud services like Dropbox for command and control activities to maintain stealth. While some research points to potential connections with other Iranian state-sponsored groups such as APT39 (Chafer APT) and Agrius APT, MalKamak exhibits distinct operational characteristics.

Aliases del actor

APT MALKAMAKOperation GhostShellShellClientdominios como www

Actores similares

apt-malkamakactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownwww.cybereason.comAPT MALKAMAK indicators and references
DLS / leak siteunknownwww.virustotal.comAPT MALKAMAK indicators and references
DLS / leak siteunknownwww.virustotal.comAPT MALKAMAK indicators and references
Repositoriounknowngithub.comAPT MALKAMAK indicators and references
DLS / leak siteunknownraw.githubusercontent.comAPT MALKAMAK indicators and references
DLS / leak siteunknownwww.cybereason.comAPT MALKAMAK indicators and references
Motivacion