Fancy Bear spotted using real Kazak government documents in spearpishing campaign
ID: 2e47b2a9-ca44-5775-89cb-80f86bfd77ad
STIX ID: report--2e47b2a9-ca44-5775-89cb-80f86bfd77ad
Feed Name: CyberScoop
Sekoia researchers observed a Russian-linked espionage campaign dubbed "Double-Tap" that weaponizes apparently legitimate Kazakhstan government documents as Word-based phishing lures; the macro chain downgrades security settings, deploys a loader called HATVIBE which fetches the CHERRYSPY backdoor, and sets persistence to run periodically. The activity—linked with medium confidence to APT28/Fancy Bear and overlapping with ZEBROCY—has impacted targets across Central Asia, East Asia and Europe, and includes documented compromises (e.g., a Tajikistan embassy email) and indicators/detection guidance published by researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
