Russia's Cozy Bear caught phishing German politicos with phony dinner invites
ID: a885781b-0247-50b2-894e-ed76aab5573a
STIX ID: report--a885781b-0247-50b2-894e-ed76aab5573a
Feed Name: The Register (Security)
Threat Score
Mandiant reports that Russian-linked APT29 (Cozy Bear) conducted a phishing campaign targeting German political parties using spoofed dinner invitations that led victims to download a ZIP containing ROOTSAW, which installs the WINELOADER backdoor from attacker-controlled domains; WINELOADER has been observed previously against diplomats and is a customized loader enabling long-term remote access and C2 communications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
