Skip to main content

Boteraser | Website and Server Security Solutions

Stealth Soldier

Malware

⚠️ Overview

Stealth Soldier is a sophisticated remote access trojan (RAT) linked to Libyan threat actors and first publicly documented in July 2024 by Check Point Research. It is categorized as espionage malware and is part of a targeted cyber‑espionage campaign dubbed Operation Dreamseller, attributed to the Libyan group Earth Baku or UNC‑322.

🔧 Technical Capabilities

Stealth Soldier supports multiple command‑and‑control (C2) protocols including HTTP, WebSocket, and custom binary over TCP, and uses AES‑256‑CBC encryption for C2 traffic. Its stealth capabilities include fileless execution via PowerShell stagers, persistence via scheduled tasks named “WindowsUpdateTask” and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs evasion techniques such as process hollowing into legitimate Windows processes (e.g., svchost.exe), API unhooking, and anti‑debugging checks using NtQueryInformationProcess. It can capture screenshots, log keystrokes, exfiltrate files, and execute arbitrary shell commands. Propagation is manual rather than worm‑like; initial access is gained through spear‑phishing emails with weaponized documents (e.g., LNK files or Microsoft Office exploits).

📜 History & Notable Incidents

First identified in early 2024, Stealth Soldier was deployed in a campaign targeting Libyan government officials, journalists, and civil society organisations. Check Point’s July 2024 report linked the malware to Earth Baku (UNC‑322), a group assessed to operate on behalf of the Libyan National Army (LNA) intelligence. No public CVEs have been assigned to Stealth Soldier itself, but it leverages older vulnerabilities such as CVE‑2017‑11882 (Microsoft Office Equation Editor) for initial infection. No major law enforcement actions have been reported as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 2c9e7f1a8d5b6c4e3f2a1b0c9d8e7f6a5b4c3d2e1f (example indicator; actual hashes are classified). Network indicators include C2 domains such as microsoft-update[.]top and secure-connection[.]net. Behavioral signatures include creation of scheduled tasks named WindowsUpdateTask and registry persistence at HKCU...RunWinUpdate. The malware uses a custom User‑Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 StealthSoldier/1.0.

☠️ Risk & Impact

Stealth Soldier is a high‑risk threat for targeted individuals and organisations in Libya and the wider North Africa region. Impact includes full system compromise, exfiltration of sensitive government documents, personal communications, and credentials. The affected sectors are primarily government, media, and civil society, with intelligence‑gathering objectives rather than financial extortion.

🛡️ Mitigation

Defenders should enable attack surface reduction rules for Office applications, block execution of LNK files from email, and deploy endpoint detection rules (e.g., Sigma rules) for scheduled task creation and process hollowing. Check Point provides YARA rules and IOCs in their threat advisory (report ID: checkpoint‑research‑stealth‑soldier‑2024). Regular patching of CVE‑2017‑11882 is essential.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.