UK uncovers novel Microsoft snooping malware, blames and sanctions GRU cyberspies
ID: d22f7039-25a9-5222-b1e3-a133699f4979
STIX ID: report--d22f7039-25a9-5222-b1e3-a133699f4979
Feed Name: The Register (Security)
The UK has attributed a newly detailed malware strain, "Authentic Antics," to Russia's APT28/GRU (unit 26165), describing how it runs inside Outlook to prompt for and harvest Microsoft credentials and OAuth tokens and to stealthily exfiltrate data by sending emails that don't appear in the victim's Sent folder; the advisory links this tooling to an ongoing GRU campaign targeting Western logistics, tech, and government entities and accompanies sanctions against identified GRU officers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
