FlyingYeti phishing crew grounded after abominable Ukraine attacks
ID: 4f2f7f46-3c18-5e79-81a7-b578e973846a
STIX ID: report--4f2f7f46-3c18-5e79-81a7-b578e973846a
Feed Name: The Register (Security)
Threat Score
Cloudflare's threat intelligence team disrupted a Russia-linked FlyingYeti phishing campaign aimed at Ukrainian residents by spoofing the Kyiv Komunalka payment portal and hosting a malicious RAR (containing COOKBOX PowerShell malware and decoy documents) on GitHub and other file hosts; Cloudflare notified GitHub and forced the actor to change hosting, delaying and increasing the cost of the operation and preventing observed successful infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
