EXECUTIVE SUMMARY:
A targeted espionage campaign has been identified against aerospace and defense sector organizations, employing a newly observed variant of the Comebacker backdoor. The malicious actor uses themed lure documents impersonating high‑profile aviation and defense entities to initiate infection, indicating a deliberate and focused threat to strategic industry targets.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A targeted espionage campaign has been identified against aerospace and defense sector organizations, employing a newly observed variant of the Comebacker backdoor. The malicious actor uses themed lure documents impersonating high‑profile aviation and defense entities to initiate infection, indicating a deliberate and focused threat to strategic industry targets.[emaillocker id="1283"]
The threat actor has deployed a newly observed variant of the Comebacker backdoor that begins with malicious Microsoft Word documents containing embedded VBA macros which rely on user execution to deliver a loader DLL and a decoy document themed around aerospace and defense topics; the loader uses the ChaCha20 stream cipher to decrypt and write a second stage loader that maps the final Comebacker payload into memory and invokes its entry point. Command and control is performed over HTTPS where the initial beacon uses a crafted URL query string and outbound data is encrypted with AES 128 CBC then Base64 encoded; server responses can instruct the malware to sleep, terminate, or download and execute additional payloads, with supplementary payloads verified by MD5, decrypted with ChaCha20, and loaded into memory to evade disk-based detection. The campaign leverages infrastructure such as open directory listing sites and multiple command and control domains discovered through pivoting and uses highly tailored lure documents that impersonate prominent aerospace and defense organizations to support a focused spear phishing approach.
It reflects the advanced capabilities of the threat actor, with custom loaders, in-memory execution, encrypted communications, tailored lures, and infrastructure pivoting all indicating long-term targeted espionage rather than opportunistic mass malware. Organizations in the aerospace, defense, and affiliated research sectors should assume they are potential targets, reinforce their macro and malware defenses, apply network detection for anomalous command-and-control traffic, and verify their endpoint resilience against multi-stage in-memory.
| Tactic | Technique Id | Technique | Sub-technique |
| Resource Development | T1583.001 | Acquire Infrastructure | Domains |
| Initial Access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1204.002 | User Execution | Malicious File |
| T1204.005 | Malicious Library | ||
| T1059.001 | Command and Scripting Interpreter | PowerShell | |
| T1059.003 | Windows Command Shell | ||
| T1059.005 | Visual Basic | ||
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| T1547.009 | Shortcut Modification | ||
| Defense Evasion | T1140 | Deobfuscate / Decode Files or Information | — |
| T1027.013 | Obfuscated Files or Information | Encrypted / Encoded File | |
| T1027.015 | Obfuscated Files or Information | Compression | |
| T1218.011 | System Binary Proxy Execution | Rundll32 | |
| T1620 | Reflective Code Loading | — | |
| Command and Control | T1132.001 | Data Encoding | Standard Encoding |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]