Libyan Oil Refinery Among Targets in Long-running Likely Espionage Campaign
A series of attacks targeting Libyan organizations, including an oil refinery, a telecoms organization, and a state institution, occurred between November 2025 and February 2026. The campaign utilized the AsyncRAT backdoor, delivered through spear-phishing emails with Libya-themed lure documents. The attackers exploited current events, such as the assassination of Saif al-Gaddafi, to gain access to networks. The modular nature of AsyncRAT and the targeted organizations suggest possible state sponsorship. The campaign's focus on Libya and its oil industry is notable, given the country's increased oil production and global energy supply concerns amidst Middle East conflicts.
Pulse ID: 69bdb8e4c95a097d1f31606a
Pulse Link: https://otx.alienvault.com/pulse/69bdb8e4c95a097d1f31606a
Pulse Author: AlienVault
Created: 2026-03-20 21:15:16
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #BackDoor #CyberSecurity #Email #Espionage #InfoSec #MiddleEast #OTX #OpenThreatExchange #Phishing #RAT #SpearPhishing #Telecom #bot #AlienVault