Frequently Asked Questions

Threat Intelligence & Campaigns

What is the Earth Bogle campaign and how does it operate?

The Earth Bogle campaign is a cyberattack operation that uses Middle Eastern geopolitical-themed lures to distribute the njRAT remote access trojan across the Middle East and North Africa. Attackers use public cloud storage services to host malware and compromised web servers to distribute it. The initial infection vector is a malicious CAB file, which loads a PowerShell script to inject njRAT into the victim's system.

How does the Earth Bogle campaign deliver njRAT to victims?

The campaign uses malicious CAB files as the first-stage loader. Once executed, a PowerShell script is used to inject njRAT into the compromised system, allowing attackers remote access and control.

What regions are primarily targeted by the Earth Bogle campaign?

The Earth Bogle campaign primarily targets entities in the Middle East and North Africa, leveraging regional geopolitical themes to increase the likelihood of successful infection.

What is njRAT and why is it dangerous?

njRAT is a remote access trojan (RAT) that allows attackers to control infected systems, steal data, log keystrokes, and deploy additional malware. Its use in targeted campaigns like Earth Bogle makes it a significant threat to organizations in the affected regions.

How does Cymulate help organizations defend against campaigns like Earth Bogle?

Cymulate enables organizations to simulate real-world cyberattacks, including campaigns like Earth Bogle, to test and validate their security defenses. By continuously assessing vulnerabilities and providing actionable remediation, Cymulate helps organizations strengthen their resilience against advanced threats such as njRAT.

What types of threats can Cymulate validate?

Cymulate validates threats across the full kill chain, including phishing, malware, lateral movement, data exfiltration, and zero-day exploits, using daily updated threat templates and AI-generated attack plans.

How quickly does Cymulate update its immediate threats module?

Cymulate's immediate threats module is updated rapidly to reflect new attacks, allowing organizations to quickly assess their IT estate for exposure to new threats and implement remedial actions promptly. Customers appreciate the speed and relevance of these updates for proactive defense. Source

What feedback have customers given about Cymulate's immediate threats module?

Customers praise the immediate threats module for its rapid updates and ability to quickly assess risk from new attacks. A Lead Cyber Defense Engineer stated: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Source

How does Cymulate enable organizations to assess emergent threats immediately?

Cymulate allows security teams to quickly evaluate their defenses against new threats. For example, Renaldo Jack, Group Cybersecurity Head at Globeleq, noted, “With Cymulate, we can almost immediately assess each of our environments against new threats.” Source

What did the Cybersecurity Head at Globeleq say about Cymulate's capabilities?

The Cybersecurity Head at Globeleq stated: “Cymulate helps understand where our gaps are and what we need to do to prevent a real attacker from moving laterally within our environment to reduce the ‘blast radius’.” Source

Features & Capabilities

What features does Cymulate offer for threat exposure validation?

Cymulate offers continuous threat validation, exposure awareness, defensive posture optimization, attack path discovery, automated mitigation, comprehensive integration with SIEM and EDR tools, and dedicated cloud security validation. These features help organizations proactively manage their cybersecurity posture. Source

Which types of threats and techniques does Cymulate simulate for endpoint security validation?

Cymulate simulates known malicious file samples, malicious behaviors, ransomware, worms, trojans, rootkits, DLL side-loading, and code injection to validate endpoint security controls. Source

How does Cymulate map to the MITRE ATT&CK® framework?

Cymulate maps its attack vectors and modules to MITRE ATT&CK® tactics, covering reconnaissance, resource development, initial access, execution, persistence, privilege escalation, defense evasion, and credential access. This ensures comprehensive security validation across the attack lifecycle. Source

What integrations does Cymulate support?

Cymulate integrates with leading security tools such as BlackBerry Cylance, Carbon Black EDR, Cisco Secure Endpoint, CrowdStrike Falcon, SentinelOne, AWS GuardDuty, Splunk, Rapid7 InsightVM, Akamai Guardicore, and more. For a full list, visit the Partnerships and Integrations page.

What is threat exposure prioritization in cybersecurity?

Threat exposure prioritization is the process of identifying and ranking vulnerabilities and security weaknesses based on their exploitability and impact on business-critical assets. Cymulate uses automated threat validation and exposure scoring to help teams focus on exposures not protected by security controls. Source

What technical documentation is available for Cymulate?

Cymulate provides a range of technical documentation, including a whitepaper on the Exposure Management Platform (CTEM), data sheets on the platform and custom attacks, and resources on technology integrations and MITRE ATT&CK® alignment. Access these at the Cymulate Resources page.

Use Cases & Benefits

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, Security Operations (SecOps) teams, Red Teams, Detection Engineers, and Vulnerability Management teams in organizations across industries such as finance, healthcare, and technology where cybersecurity is critical. Source

What business impact can customers expect from using Cymulate?

Customers typically achieve a 30% improvement in threat prevention, a 52% reduction in critical exposures, a 60% increase in operational efficiency, 40X faster threat validation, and an 81% reduction in cyber risk within four months. Source

What are some case studies demonstrating Cymulate's effectiveness?

Case studies include Hertz Israel reducing cyber risk by 81% in four months, Nemours Children's Health improving detection and response, Nedbank focusing on critical vulnerabilities, and GUD Holdings establishing consistent security metrics across subsidiaries. See more at the Cymulate Customers page.

How does Cymulate address the pain points of security teams?

Cymulate addresses overwhelming threats, lack of visibility, unclear prioritization, operational inefficiencies, fragmented tools, cloud complexity, and communication barriers by providing continuous threat validation, actionable insights, automation, and unified exposure management. Source

How does Cymulate's solution differ for Red Teams, Detection Engineers, and Vulnerability Management teams?

For Red Teams, Cymulate offers production-safe attack simulations and automates custom offensive testing. Detection Engineers benefit from identifying SIEM coverage gaps and validating detection rules. Vulnerability Management teams get consolidated exposure prioritization and efficiency gains in remediation. Source

What types of cyber threats does the financial services sector face?

The financial services sector faces sophisticated threats such as ransomware, phishing, and advanced persistent threats (APTs), requiring robust security controls for both internal systems and customer-facing applications. Source

What constitutes an insider threat?

An insider threat is a security risk originating from within an organization, such as current or former employees, contractors, or partners with legitimate access. Insider threats can be malicious, negligent, or compromised users whose credentials are stolen by attackers. Source

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate holds SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications, demonstrating adherence to industry-leading security and privacy standards. Source

How does Cymulate ensure GDPR compliance?

Cymulate ensures GDPR readiness through data protection by design, secure development practices, and a dedicated privacy and security team, including a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Source

Where is Cymulate hosted and how is data protected?

Cymulate's services are hosted in secure AWS data centers that are ISO 27001, PCI DSS, and SOC 2/3 compliant. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Source

What application security practices does Cymulate follow?

Cymulate follows a strict Secure Development Lifecycle (SDLC), including secure code training, continuous vulnerability scanning, software composition analysis, and annual third-party penetration tests. Source

Implementation & Support

How long does it take to implement Cymulate?

Cymulate is known for its quick deployment process. Customers can start running simulations almost immediately after deployment, with no additional hardware or complex configurations required. Source

How easy is Cymulate to use?

Customers consistently praise Cymulate for its intuitive and user-friendly design. The platform is easy to implement and operate, with a user-friendly dashboard and minimal resource requirements. Source

What support options are available for Cymulate customers?

Cymulate provides email support, real-time chat support, and access to educational resources such as webinars, e-books, and a knowledge base. Email Support | Chat Support

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate delivers the industry's leading threat scenario library and AI-powered capabilities to streamline workflows and accelerate security posture. AttackIQ lacks the same level of innovation, threat coverage, and ease of use. Read more

How does Cymulate compare to Mandiant Security Validation?

Mandiant's platform has seen minimal innovation in recent years, while Cymulate continually innovates with AI and automation, expanding into the exposure management market as a grid leader. Read more

How does Cymulate compare to Pentera?

Pentera focuses on attack path validation but lacks the depth Cymulate provides in fully assessing and strengthening defenses. Cymulate optimizes defense, scales offensive testing, and increases exposure awareness. Read more

How does Cymulate compare to Picus Security?

Picus is suitable for on-premise BAS needs but lacks Cymulate's comprehensive exposure validation platform, which covers the full kill chain and includes cloud control validation. Read more

How does Cymulate compare to SafeBreach?

Cymulate outpaces SafeBreach with unmatched innovation, precision, and automation. Cymulate offers the industry's largest attack library, a full CTEM solution, and comprehensive exposure validation. Read more

How does Cymulate compare to Scythe?

Scythe is suitable for advanced red teams but lacks Cymulate's ease of use, daily threat updates, and comprehensive control validation. Cymulate provides actionable remediation and automated mitigation. Read more

How does Cymulate compare to NetSPI?

NetSPI is a PTaaS vendor, while Cymulate offers a platform for continuous, independent assessment and defense strengthening. Cymulate is recognized as a leader in exposure validation by Gartner and G2. Read more

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized based on the chosen package, number of assets, and scenarios required. For a tailored quote, organizations can schedule a demo with Cymulate's team. Source

Company & Vision

What is Cymulate's vision and mission?

Cymulate's vision is to lead the way in how companies think about and implement cybersecurity strategies, making the world a safer place. Its mission is to empower organizations worldwide against threats and make advanced cybersecurity as simple and familiar as sending an email. Source

What is Cymulate's company history and global presence?

Cymulate was founded in 2016 and has a global presence with offices in eight locations and customers in 50 countries. Over 1,000 customers trust Cymulate to enhance their cybersecurity posture. Source

Video Resources

Where can I watch the Threat Exposure Validation Summer Series: Threat Exposure Validation is a must have in 2025?

You can watch the video Threat Exposure Validation Summer Series: Threat Exposure Validation is a must have in 2025 for insights into the importance of threat exposure validation in modern cybersecurity strategies.

Where can I watch npm Under Siege: Worms, Toolchains and the Next Evolution of Supply Chain Attacks?

You can watch the video npm Under Siege: Worms, Toolchains and the Next Evolution of Supply Chain Attacks to learn about the latest trends in supply chain attacks and how to defend against them.

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Earth Bogle Campaign Deploys njRAT via Geopolitical Lures

January 19, 2023

Middle Eastern geopolitical themed lures were used to distribute njRAT across the Middle East and North Africa.
Public cloud storage services were utilized to host malware while compromised web servers were used to distribute the malicious remote access trojan.
A malicious CAB file was used as the first stage loader while a PowerShell script injected njRAT into the compromised system.