logo

Fancy Bear spotted using real Kazak government documents in spearpishing campaign

ID: 2e47b2a9-ca44-5775-89cb-80f86bfd77ad

STIX ID: report--2e47b2a9-ca44-5775-89cb-80f86bfd77ad

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2025-01-13

Date Updated: 2026-04-21

Author: mbracken

...
...

Sekoia researchers observed a Russian-linked espionage campaign dubbed "Double-Tap" that weaponizes apparently legitimate Kazakhstan government documents as Word-based phishing lures; the macro chain downgrades security settings, deploys a loader called HATVIBE which fetches the CHERRYSPY backdoor, and sets persistence to run periodically. The activity—linked with medium confidence to APT28/Fancy Bear and overlapping with ZEBROCY—has impacted targets across Central Asia, East Asia and Europe, and includes documented compromises (e.g., a Tajikistan embassy email) and indicators/detection guidance published by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.