UnsolicitedBooker Targets Telecoms in Central Asia with New Backdoors

UnsolicitedBooker Targets Telecoms in Central Asia with New Backdoors

First seen 25 Feb 2026, 21:11 UTC RescanaScworld 86% similarity 32.7

Article Content

Browse articles
ThreatCluster

The China-aligned APT group UnsolicitedBooker has intensified cyber-espionage operations against telecommunications companies in Kyrgyzstan and Tajikistan. The group has deployed two sophisticated backdoors, LuciDoor and MarsSnake, utilizing tailored spear-phishing campaigns to compromise these organizations. This marks a shift from their previous focus on Saudi Arabian targets.

ThreatCluster AI How this analysis works

Timeline

2023-03-01
UnsolicitedBooker identified as active threat actor
Recent
UnsolicitedBooker targets telecoms in Kyrgyzstan and Tajikistan
Recent
Deployment of LuciDoor and MarsSnake backdoors reported

Community

Browse all →