UnsolicitedBooker
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:22:52
Targeted industries: government-and-public-sector
Targeted regions: country_code:sa country_code:cn country_code:in country_code:ae country_code:za
Context
UnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi Arabia, employing a backdoor called MarsSnake. The group utilizes spear-phishing emails, often featuring flight tickets as decoys, to infiltrate governmental organizations across Asia, Africa, and the Middle East. Their operations have included multiple intrusion attempts over several years, demonstrating a sustained interest in their target. MarsSnake provides significant control over infected machines, allowing for arbitrary command execution and file access.
Reports & references
- ESET — Eset Apt Activity Report Q4 2024Q1 2025 Malware Sharing Wipers Exploits (report)