Actor240524 — APT Profile

Actor240524 is a cluster NSFOCUS Security Labs says it first observed on 1 July 2024, directed at diplomatic staff in Azerbaijan and Israel through targeted phishing mail. The lure was a macro-bearing Word file named iden.doc whose decoy content, blurred images of Azerbaijani government paperwork presented in Azerbaijani, was tailored to that audience. Two custom components followed: ABCloader, which decrypts and launches the next stage, and ABCsync, a remote access trojan able to run shell commands, pull files off the host and alter data on it, communicating with its controller over encrypted UDP. Per NSFOCUS, ABCsync carries an unusually heavy anti-analysis layer, including encrypted strings and API names, PEB-based debugger checks, hardware-breakpoint detection, and virtual-machine tests that inspect screen resolution and running-process counts. NSFOCUS read the targeting as an attempt to strain cooperation between the two governments and judged the toolkit still unfinished, since several of its commands only yield a result in combination.

Tools & malware

Vendor research

Read the full analysis on IntelFusions