Cyber threat hunters have revealed the tactics of a Chinese hacking group known as UnsolicitedBooker, which targeted an unnamed international organization in Saudi Arabia using a previously unknown digital backdoor codenamed MarsSnake.
See also: Chinese hackers hit the drone sector

Cybersecurity firm ESET, which first detected the group's intrusions in March 2023 and again a year later, said the activity relied on spear-phishing via emails containing flight ticket bait to infiltrate their targets. The attacks are characterized by the use of remote access (backdoors) such as Chinoxy, DeedRAT, Poison Ivy and BeRAT, which are widely used by Chinese hacking groups.
The UnsolicitedBooker group appears to share similarities with the Space Pirates threat network as well as another, as yet unattributed, cluster of malicious activity that used the Zardoor toolkit to attack an Islamic non-profit organization in Saudi Arabia.
The most recent campaign, which the Slovak cybersecurity firm detected in January 2025, involved sending a phishing email that appeared to come from Saudia Airlines and was about booking a flight, addressed to the same organization in Saudi Arabia.
See also: Chinese hackers exploit SAP NetWeaver vulnerability
The Word document, once opened, triggers the execution of a VBA macro, which decodes and writes to the file system an executable file named “smssdrvhost.exe”. This file acts as a loader for MarsSnake, a backdoor malware that establishes communication with a remote server (“contact.decenttoy[.]top”).

This revelation comes as another Chinese cyberespionage, known as PerplexedGoblin (or APT31), reportedly targeted a government agency in Central Europe in December 2024, installing a spying backdoor called NanoSlate.
ESET also reported that it has detected continued attacks by the DigitalRecyclers on European Union government organizations. The group leverages the KMA VPN operational relay box (ORB) to hide its online activity and uses the malicious tools RClient, HydroRShell , and GiftBox to gain access and collect data.
DigitalRecyclers was first detected by ESET in 2021, although it is estimated to have been active since at least 2018 .
See also: Hackers install backdoor in Unitree Go1 robot dogs
The incidents are part of a broader pattern of increased cyber espionage attributed to state-sponsored Chinese threat groups (Advanced Persistent Threats – APTs). These attacks primarily target government, diplomatic and critical organizations, primarily in geopolitically sensitive regions such as the Middle East and the European Union.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
