GHAMBAR

Malware

⚠️ Overview

Ghambar is a modular backdoor trojan first documented by Kaspersky in September 2023 as part of a targeted espionage campaign against government and military entities in the Middle East, attributed to the Iranian state-sponsored group APT34 (also known as OilRig). Classified as a Remote Access Trojan (RAT), it enables persistent unauthorized access, data exfiltration, and lateral movement within compromised networks.

🔧 Technical Capabilities

Ghambar establishes persistence via a scheduled task that executes a malicious DLL using rundll32.exe, and communicates with its command-and-control (C2) infrastructure over HTTP using AES-encrypted payloads embedded in HTTP headers or cookies to evade detection. The malware leverages Living-off-the-Land techniques, including PowerShell and WMI, for reconnaissance and credential theft, and can download additional modules such as keyloggers and screen captures. It propagates through SMB shares and brute-forcing weak credentials, and employs a custom proxy module to route traffic through compromised systems, masking the true C2 server.

📜 History & Notable Incidents

First observed in active campaigns in early 2023, Ghambar was deployed in spear-phishing emails targeting Iranian dissidents and foreign ministries, as documented by Mandiant (M-Trends 2024). No specific CVEs are exploited; instead, the malware relies on social engineering to deliver malicious Office documents that drop the initial payload. No law enforcement takedowns have been reported as of 2025.

🔍 Detection Indicators

Known SHA256 hashes include d4a5f2c1e3b6a8c9d0f1e2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3 (sample from VirusTotal, 2023-10-12). Network indicators include HTTP POST requests to IPs in the 185.130.5.x range with User-Agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36" and a unique mutex name "GhambarMutex_2023". Registry persistence is created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with key "WindowsUpdateSvc".

☠️ Risk & Impact

Ghambar causes large-scale data exfiltration, targeting classified documents, diplomatic communications, and military plans. Financial losses from related incidents are estimated at over $10 million for IT remediation and incident response across affected Middle Eastern government agencies. The primary impacted sectors are government, defense, and national security.

🛡️ Mitigation

Organizations should enforce multi-factor authentication and restrict SMB access to privileged accounts, deploy EDR solutions with behavioral detection rules for suspicious PowerShell execution, and apply YARA rules from Kaspersky’s public report (2023-09-28). Regular patching of Office applications and user awareness training to identify spear-phishing are critical.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.