logo

Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022

ID: 92a0115c-b33a-5b9c-9756-907c0c41cfcf

STIX ID: report--92a0115c-b33a-5b9c-9756-907c0c41cfcf

Feed Name: BushidoToken Blog

Threat Score
90/100

Date Published: 2022-06-27

Date Updated: 2026-06-07

...
...

This report compiles OSINT and vendor findings on Russian APT activity (FancyBear/APT28 and CozyBear/APT29) in the first half of 2022, documenting widespread credential-phishing campaigns, newly observed malware (including a .NET infostealer and CredoMap), exploitation of the MSDT Follina RCE (CVE-2022-30190), abuse of legitimate cloud APIs (Trello, Dropbox) for C2/exfiltration, and links to prior supply-chain intrusions (SolarWinds); it concludes with IOCs and actionable mitigations for detection, patching, and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.