Threat hunters have exposed the tactics of a China-aligned threat actor called UnsolicitedBooker that targeted an unnamed international organization in Saudi Arabia with a previously undocumented backdoor dubbed MarsSnake.
ESET, which first discovered the hacking group’s intrusions targeting the entity in March 2023 and again a year later, said the activity leverages spear-phishing emails using
ESET, which first discovered the hacking group’s intrusions targeting the entity in March 2023 and again a year later, said the activity leverages spear-phishing emails using







![[Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications](https://encircle-it.com/wp-content/uploads/2026/04/webinar-from-code-to-cloud-to-soc-learn-a-smarter-way-to-defend-modern-applications-3.webp)


