Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CamelClone Espionage Targets Governments via File-Sharing

CamelClone Espionage Targets Governments via File-Sharing

Posted on March 17, 2026 By CWS

A recent cyber espionage operation, known as CamelClone, has been identified as a significant threat to government entities, defense sectors, and diplomatic missions in various countries, including Algeria, Mongolia, Ukraine, and Kuwait. This campaign employs spear-phishing tactics, leveraging ZIP files masquerading as official documents to initiate a series of malicious activities culminating in data theft via a legitimate cloud tool.

Operation Overview

The CamelClone operation came to light in late February 2026, when a suspicious ZIP file associated with Algeria’s Ministry of Housing was detected on VirusTotal. This file, uploaded from Algeria on February 24, marked the beginning of a series of targeted attacks. Subsequent files targeted Mongolia with themes around China cooperation, and further samples referenced Algerian-Ukrainian proposals and Kuwait’s Air Force, showcasing the operation’s broad geographical focus.

Strategic Targeting

Analysis by Seqrite highlights that despite the diverse targets, each country holds strategic importance in global geopolitics. Ukraine is entrenched in ongoing conflict, Algeria is pivotal in energy politics, Mongolia navigates complex relations with China and Russia, and Kuwait holds a key defense position in the Gulf. The attackers seem driven by intelligence gathering rather than financial gain.

Technical Execution

The attack methodology is consistent across all identified cases, utilizing ZIP archives containing LNK files with official-looking logos. When opened, a hidden PowerShell command activates, fetching subsequent attack stages from an anonymous file-sharing service. The absence of dedicated command servers, with all payloads hosted on filebulldogs[.]com and data routed through MEGA, complicates detection efforts.

Once initiated, the infection chain downloads and executes a JavaScript file, tracked as HOPPINGANT, which employs Base64-encoded PowerShell commands to further the attack. A decoy PDF distracts victims while a ZIP file with the Rclone tool is utilized to exfiltrate data, including sensitive documents and Telegram session information, to MEGA accounts linked to anonymous emails.

Defense Measures

Organizations in the government, defense, and diplomatic sectors should exercise caution with unsolicited ZIP files, particularly those referencing official matters. Blocking access to file-sharing services and monitoring data transfers to cloud platforms can reduce risk exposure. Additionally, limiting LNK file executions from untrusted sources and using behavior-based security tools can thwart these PowerShell and JavaScript exploits before they fully execute.

Stay informed by following us on Google News, LinkedIn, and X. Set CSN as a preferred source on Google for more updates.

Cyber Security News Tags:CamelClone, Cybersecurity, Espionage, file-sharing, government security, Mega, Operation CamelClone, PowerShell, Rclone, spear-phishing

Post navigation

Previous Post: Handala Hack Targets US, Israel with Destructive Cyberattacks
Next Post: Stryker Faces Major Cyberattack by Iran-Linked Group

Related Posts

New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines Cyber Security News
GitHub RCE Flaw Threatens Server Security GitHub RCE Flaw Threatens Server Security Cyber Security News
Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials Cyber Security News
Pakistani Actors Built 300+ Cracking Websites Used to Deliver Info-Stealer Malware Pakistani Actors Built 300+ Cracking Websites Used to Deliver Info-Stealer Malware Cyber Security News
Microsoft to Kill Popular Editor Browser Extensions on Edge and Chrome Microsoft to Kill Popular Editor Browser Extensions on Edge and Chrome Cyber Security News
Claude Opus 4.6 Unveils 500+ Critical Vulnerabilities Claude Opus 4.6 Unveils 500+ Critical Vulnerabilities Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet Alerts on Credential Attack Targeting FortiGate
  • GentleKiller Exploits Drivers to Bypass 400+ Security Tools
  • CyberSentinel AI Revolutionizes Security with 33 Tools
  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet Alerts on Credential Attack Targeting FortiGate
  • GentleKiller Exploits Drivers to Bypass 400+ Security Tools
  • CyberSentinel AI Revolutionizes Security with 33 Tools
  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark