Menu
Browse

Turkish government entity

Primary URL Location Industry
www[.]mfa[.]gov[.]tr
Country Turkey
Government - National Icon
Government - National
Profile

The organisation is a Turkish government entity with its headquarters located in Turkey. In November 2018, it became the target of a cyber espionage operation conducted by the Iran-linked Chafer APT group. The attackers deployed a custom Python-based backdoor referred to as MechaFlounder against the entity. The initial infection vector involved the domain win10-update[.]com, which hosted the malicious payload.

The MechaFlounder malware was packaged using PyInstaller to facilitate execution on Windows systems. Once installed, the backdoor provided the adversaries with capabilities for file transfer, arbitrary command execution, and sustained communication with command‑and‑control servers over HTTP. The campaign reused infrastructure previously observed in other Chafer operations, indicating a continuity of tactics. Analysis of the code revealed similarities with tools associated with the Oilrig threat group, suggesting possible code‑sharing between the two actors. To obfuscate its output, the malware encoded command results in base16 before transmission. For data exfiltration, it leveraged the Python mechanize module to interact with web resources and harvest information. The overall design of MechaFlounder points to a focus on surveillance and the theft of sensitive governmental data.

Incidents
Linked incidents available to members
1 incident