Turkish government entity
| Primary URL | Location | Industry | www[.]mfa[.]gov[.]tr |
Country
Turkey
|
Government - National
|
|---|
Profile
The organisation is a Turkish government entity with its headquarters located in Turkey. In November 2018, it became the target of a cyber espionage operation conducted by the Iran-linked Chafer APT group. The attackers deployed a custom Python-based backdoor referred to as MechaFlounder against the entity. The initial infection vector involved the domain win10-update[.]com, which hosted the malicious payload.
The MechaFlounder malware was packaged using PyInstaller to facilitate execution on Windows systems. Once installed, the backdoor provided the adversaries with capabilities for file transfer, arbitrary command execution, and sustained communication with command‑and‑control servers over HTTP. The campaign reused infrastructure previously observed in other Chafer operations, indicating a continuity of tactics. Analysis of the code revealed similarities with tools associated with the Oilrig threat group, suggesting possible code‑sharing between the two actors. To obfuscate its output, the malware encoded command results in base16 before transmission. For data exfiltration, it leveraged the Python mechanize module to interact with web resources and harvest information. The overall design of MechaFlounder points to a focus on surveillance and the theft of sensitive governmental data.
