Scworld
UnsolicitedBooker Targets Telecoms in Central Asia with New Backdoors
First seen 25 Feb 2026, 21:11 UTC
•
•86% similarity
•32.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The China-aligned APT group UnsolicitedBooker has intensified cyber-espionage operations against telecommunications companies in Kyrgyzstan and Tajikistan. The group has deployed two sophisticated backdoors, LuciDoor and MarsSnake, utilizing tailored spear-phishing campaigns to compromise these organizations. This marks a shift from their previous focus on Saudi Arabian targets.
ThreatCluster AI
How this analysis works
Timeline
2023-03-01
UnsolicitedBooker identified as active threat actor
Recent
UnsolicitedBooker targets telecoms in Kyrgyzstan and Tajikistan
Recent
Deployment of LuciDoor and MarsSnake backdoors reported