Skip to content
UnsolicitedBooker Targets Telecoms in Central Asia with New Backdoors

UnsolicitedBooker Targets Telecoms in Central Asia with New Backdoors

First seen 25 Feb 2026, 21:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

The China-aligned APT group UnsolicitedBooker has intensified cyber-espionage operations against telecommunications companies in Kyrgyzstan and Tajikistan. The group has deployed two sophisticated backdoors, LuciDoor and MarsSnake, utilizing tailored spear-phishing campaigns to compromise these organizations. This marks a shift from their previous focus on Saudi Arabian targets.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 203d ago How this analysis works

Timeline

2023-03-01
UnsolicitedBooker identified as active threat actor
Recent
UnsolicitedBooker targets telecoms in Kyrgyzstan and Tajikistan
Recent
Deployment of LuciDoor and MarsSnake backdoors reported

More articles in this cluster (2)

Following this threat?

Track Mustang Panda and LuciDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed