A previously undocumented polyglot malware is being deployed in attacks against airlines, satellite communications, and critical transportation organizations in the United Arab Emirates.
See also: Bitter Group targets defense sector with WmRAT and MiyaRAT malware

The malware provides a backdoor called Sosano, which establishes permanent access to infected devices and allows attackers to execute commands remotely.
The activity was discovered by Proofpoint in October 2024, which states that the attacks are linked to a threat actor called “UNK_CraftyCamel.” While the campaign is still small, researchers report that it is advanced and dangerous for the targeted companies.
Proofpoint researchers noted that the attacks bear similarities to operations by Iran-aligned TA451 and TA455 groups. However, the most recent campaign is distinct, with a strong focus on cyberespionage .
Polyglot malware consists of specially crafted files that contain multiple file formats, allowing them to be interpreted differently by different applications. For example, a single file could be structured as both a valid MSI (Windows installer) and a JAR (Java archive), resulting in Windows recognizing it as an MSI while Java interprets it as a JAR.
This technique allows attackers to secretly deliver malicious payloads while avoiding security software, which typically analyzes files based on a uniform format.
In the new campaign observed by Proofpoint, the attack begins with a highly targeted phishing email sent by a compromised Indian electronics company (INDIC Electronics). These emails contain malicious URLs that direct victims to a fake domain (indicelectronics[.]net), where they are asked to download a ZIP file (“OrderList.zip”).
See also: The Mask APT returns with Multi-Platform Malware Arsenal

The file contains a LNK file (Windows shortcut) disguised as XLS, as well as two PDF files (“about-indic.pdf” and “electronica-2024.pdf”). Both PDFs are polyglot files that contain a legitimate PDF file structure but also an additional malicious file structure. The first PDF contains HTA (HTML Application) code, while the other contains a hidden ZIP file.
The main advantage of using polyglot malware is to avoid detection, as most security tools will inspect the first file format (PDF), which is a benign document, and completely ignore the malicious hidden part (HTA/ZIP payloads).
When the LNK file is executed, cmd.exe launches mshta.exe , which executes the HTA script hidden within the first PDF, triggering the launch of the second PDF file. The hidden file within the second PDF writes a URL file to the Windows registry for persistence, and then executes an XOR -encoded JPEG file that decodes a DLL payload (“yourdllfinal.dll”), which is the Sosano backdoor .
Proofpoint says Sosano is a relatively simple payload with limited functionality, which was likely bloated to 12 MB in size to hide the small amounts of malicious code it uses.
Once activated, Sonaso establishes a connection to the command and control (C2) server at “bokhoreshonline[.]com” and awaits commands, including file operations, executing shell commands, and retrieving and launching additional payloads.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New Meeten malware targets macOS and Windows users
Polyglot malware refers to a type of malware that can exploit multiple flaws or features across different environments or platforms. The term “polyglot” usually refers to something that can run in many different programming languages. When applied to malware, it means that the code is designed to run across multiple environments, often by exploiting different systems, protocols, or languages in a single file or piece of code.
Source: bleepingcomputer
