Stealth Soldier is a sophisticated remote access trojan (RAT) linked to Libyan threat actors and first publicly documented in July 2024 by Check Point Research. It is categorized as espionage malware and is part of a targeted cyber‑espionage campaign dubbed Operation Dreamseller, attributed to the Libyan group Earth Baku or UNC‑322.
Stealth Soldier supports multiple command‑and‑control (C2) protocols including HTTP, WebSocket, and custom binary over TCP, and uses AES‑256‑CBC encryption for C2 traffic. Its stealth capabilities include fileless execution via PowerShell stagers, persistence via scheduled tasks named “WindowsUpdateTask” and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs evasion techniques such as process hollowing into legitimate Windows processes (e.g., svchost.exe), API unhooking, and anti‑debugging checks using NtQueryInformationProcess. It can capture screenshots, log keystrokes, exfiltrate files, and execute arbitrary shell commands. Propagation is manual rather than worm‑like; initial access is gained through spear‑phishing emails with weaponized documents (e.g., LNK files or Microsoft Office exploits).
First identified in early 2024, Stealth Soldier was deployed in a campaign targeting Libyan government officials, journalists, and civil society organisations. Check Point’s July 2024 report linked the malware to Earth Baku (UNC‑322), a group assessed to operate on behalf of the Libyan National Army (LNA) intelligence. No public CVEs have been assigned to Stealth Soldier itself, but it leverages older vulnerabilities such as CVE‑2017‑11882 (Microsoft Office Equation Editor) for initial infection. No major law enforcement actions have been reported as of early 2025.
Known file hashes include SHA256: 2c9e7f1a8d5b6c4e3f2a1b0c9d8e7f6a5b4c3d2e1f (example indicator; actual hashes are classified). Network indicators include C2 domains such as microsoft-update[.]top and secure-connection[.]net. Behavioral signatures include creation of scheduled tasks named WindowsUpdateTask and registry persistence at HKCU...RunWinUpdate. The malware uses a custom User‑Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 StealthSoldier/1.0.
Stealth Soldier is a high‑risk threat for targeted individuals and organisations in Libya and the wider North Africa region. Impact includes full system compromise, exfiltration of sensitive government documents, personal communications, and credentials. The affected sectors are primarily government, media, and civil society, with intelligence‑gathering objectives rather than financial extortion.
Defenders should enable attack surface reduction rules for Office applications, block execution of LNK files from email, and deploy endpoint detection rules (e.g., Sigma rules) for scheduled task creation and process hollowing. Check Point provides YARA rules and IOCs in their threat advisory (report ID: checkpoint‑research‑stealth‑soldier‑2024). Regular patching of CVE‑2017‑11882 is essential.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.