The Stealth Soldier campaign marks the possible reemergence of a threat actor known as “The Eye on the Nile” since its last operation in 2019.

Check Point Research recently uncovered a series of highly targeted espionage attacks in Libya, shedding light on the Stealth Soldier backdoor. This sophisticated malware operates as a custom modular backdoor with surveillance capabilities including file leakage, screen and microphone recording, keystroke logging, and browser information theft.
The campaign, which appears to target Libyan organizations, marks the possible re-emergence of a threat actor known as “The Eye on the Nile” since its last operation in 2019.
Stealth Soldier, an implant used in limited and targeted attacks, is actively maintained with the latest version, version 9, compiled in February 2023. CheckPoint Research's investigation began with the discovery of multiple files submitted to VirusTotal between November 2022 and January 2023 from Libya.
These files, named in Arabic such as “هام وعاجل.exe” (Important and Urgent.exe) and “برقية 401.exe” (Telegram 401.exe), turned out to be downloaders for different versions of the Stealth Soldier malware.
The Stealth Soldier execution flow begins with the downloader, which triggers the infection chain. Although the downloader's delivery mechanism remains unknown, social engineering.
The malware infection process involves downloading multiple files from the Command and Control (C&C) server, including a loader, a watchdog, and a payload. These components work together to create persistence and perform surveillance functions.
First, the loader downloads an internal module called PowerPlus to enable PowerShell commands and create persistence. Then, the watchdog periodically checks for updated versions of the loader and executes it accordingly. Finally, the loader collects data, receives commands from the C&C server, and executes various modules based on the attacker's instructions.
The Stealth Soldier payload collects the victim's information, including hostname, username, drive list, and files in specific directories. This malware supports various commands, such as directory listing, file upload, screenshot capture, microphone recording, keystroke logging, browser credentials extraction, and PowerShell command execution.
Check Point Research identified three different versions of Stealth Soldier (versions 6, 8, and 9), each with minor variations in functionality, file names, and persistence mechanisms.

Additionally, the investigation uncovered a number of phishing domains linked to the campaign, with some masquerading as websites belonging to the Libyan. The phishing domains, which are hosted on IP addresses associated with previous malicious activity, indicated a possible intent to conduct phishing campaigns.
Check Point Research also discovered similarities between this recent operation and the “Eye on the Nile” campaign, which was previously linked to government-backed actors by Amnesty International and Check Point Research. The overlapping infrastructure suggests a possible connection between the two campaigns, indicating the persistence and adaptability of the threat actor behind them.
The Stealth Soldier malware campaign targeting Libyan organizations highlights the increasing sophistication of cyberespionage. The use of custom backdoors and advanced surveillance capabilities poses significant threats to the data and privacy of targeted entities.
Detecting and mitigating advanced threats like Stealth Soldier requires a combination of proactive threat intelligence, awareness , and effective security solutions to ensure a resilient defense against evolving cyber threats.
Information source: hackread.com
