MalKamak

First seen
2018-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:10:14

Targeted industries: defense-and-aerospace technology-and-telecommunications

Context

MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.

Reports & references

  • cybereason.com — Operation Ghostshell Novel Rat Targets Global Aerospace And Telecoms Firms (report)

External references