UnsolicitedBooker

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:22:52

Targeted industries: government-and-public-sector

Targeted regions: country_code:sa country_code:cn country_code:in country_code:ae country_code:za

Context

UnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi Arabia, employing a backdoor called MarsSnake. The group utilizes spear-phishing emails, often featuring flight tickets as decoys, to infiltrate governmental organizations across Asia, Africa, and the Middle East. Their operations have included multiple intrusion attempts over several years, demonstrating a sustained interest in their target. MarsSnake provides significant control over infected machines, allowing for arbitrary command execution and file access.

Reports & references

  • ESET — Eset Apt Activity Report Q4 2024Q1 2025 Malware Sharing Wipers Exploits (report)

External references