HomeSecurityChinese Hackers Target Saudi Organization with MarsSnake Backdoor

Chinese Hackers Target Saudi Organization with MarsSnake Backdoor

Cyber ​​threat hunters have revealed the tactics of a Chinese hacking group known as UnsolicitedBooker, which targeted an unnamed international organization in Saudi Arabia using a previously unknown digital backdoor codenamed MarsSnake.

See also: Chinese hackers hit the drone sector

MarsSnake Backdoor

Cybersecurity firm ESET, which first detected the group's intrusions in March 2023 and again a year later, said the activity relied on spear-phishing via emails containing flight ticket bait to infiltrate their targets. The attacks are characterized by the use of remote access (backdoors) such as Chinoxy, DeedRAT, Poison Ivy and BeRAT, which are widely used by Chinese hacking groups.

The UnsolicitedBooker group appears to share similarities with the Space Pirates threat network as well as another, as yet unattributed, cluster of malicious activity that used the Zardoor toolkit to attack an Islamic non-profit organization in Saudi Arabia.

The most recent campaign, which the Slovak cybersecurity firm detected in January 2025, involved sending a phishing email that appeared to come from Saudia Airlines and was about booking a flight, addressed to the same organization in Saudi Arabia.

See also: Chinese hackers exploit SAP NetWeaver vulnerability

The Word document, once opened, triggers the execution of a VBA macro, which decodes and writes to the file system an executable file named “smssdrvhost.exe”. This file acts as a loader for MarsSnake, a backdoor malware that establishes communication with a remote server (“contact.decenttoy[.]top”).

Chinese Hackers Target Saudi Organization with MarsSnake Backdoor

This revelation comes as another Chinese cyberespionage, known as PerplexedGoblin (or APT31), reportedly targeted a government agency in Central Europe in December 2024, installing a spying backdoor called NanoSlate.

ESET also reported that it has detected continued attacks by the DigitalRecyclers on European Union government organizations. The group leverages the KMA VPN operational relay box (ORB) to hide its online activity and uses the malicious tools RClient, HydroRShell , and GiftBox to gain access and collect data.

DigitalRecyclers was first detected by ESET in 2021, although it is estimated to have been active since at least 2018 .

See also: Hackers install backdoor in Unitree Go1 robot dogs

The incidents are part of a broader pattern of increased cyber espionage attributed to state-sponsored Chinese threat groups (Advanced Persistent Threats – APTs). These attacks primarily target government, diplomatic and critical organizations, primarily in geopolitically sensitive regions such as the Middle East and the European Union.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS