ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Mysterious Elephant APT Group Leverages Hajj-Themed Lures in Advanced Malware Campaign

South Asian Threat Actor Enhances Attack Arsenal with Updated Asyncshell Variant

Kyle by Kyle
November 22, 2024
in Malware
Reading Time: 2 mins read
Elephant APT Group Leverages Hajj Themed Asyncshell
Share on FacebookShare on Twitter

The notorious threat actor Mysterious Elephant (also known as APT-K-47) has been detected orchestrating a sophisticated cyber attack campaign utilizing an advanced version of the Asyncshell malware. Security researchers at Knownsec 404 have uncovered evidence of the group exploiting Hajj-themed lures to deceive victims into executing malicious payloads disguised as Microsoft Compiled HTML Help (CHM) files.

Background and Targeting

Mysterious Elephant, which emerged in 2022, has primarily focused its operations on Pakistani entities. The group’s tactical approach and toolset share notable similarities with other regional threat actors, including SideWinder, Confucius, and Bitter. Their activities gained significant attention in October 2023 when they conducted a spear-phishing campaign delivering the ORPCBackdoor malware across Pakistan and neighboring countries.

Latest Attack Methodology

While the initial access vector remains unconfirmed, researchers believe the group relies on phishing emails to distribute a ZIP archive containing two components:

  • A CHM file purportedly related to the 2024 Hajj policy
  • A concealed executable file

encrypted zip malware

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

The attack sequence begins when victims open the CHM file, which displays a legitimate PDF document hosted on Pakistan’s Ministry of Religious Affairs and Interfaith Harmony website. Simultaneously, the hidden malicious executable activates in the background.

Asyncshell Evolution

The malware’s primary function is establishing a command shell connection with a remote server. Researchers have identified four distinct versions of Asyncshell since its initial deployment in late 2023. Key developments include:

  • Enhanced capabilities for executing cmd and PowerShell commands
  • Exploitation of the WinRAR vulnerability (CVE-2023-38831)
  • The transition from TCP to HTTPS for command-and-control communications
  • Implementation of an updated attack sequence utilizing Visual Basic Script
  • Introduction of scheduled tasks for payload execution

Strategic Improvements

According to Knownsec 404’s analysis, APT-K-47 has demonstrated significant advancement in its operational sophistication. The group has implemented disguised service requests to control shell server addresses, moving away from fixed command-and-control infrastructure to variable C2 servers. This strategic shift highlights the group’s growing investment in Asyncshell as a primary attack tool.

Previous Post

Holiday Shoppers Beware: Sophisticated Phishing Campaign Targets Black Friday Deals

Next Post

Malware Exploits Avast Anti-Rootkit Driver to Disable Security Software

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.