logo

New Malware Attributed to Russian Hacking Group APT28

ID: 8beca94f-6404-5590-bf8e-c8a94ca90522

STIX ID: report--8beca94f-6404-5590-bf8e-c8a94ca90522

Feed Name: SecurityScorecard Blog

Threat Score
85/100

Date Published: 2024-06-28

Date Updated: 2026-04-29

...
...

This report summarizes CERT‑UA and SecurityScorecard findings that APT28 (Fancy Bear) has been using a new backdoor called OCEANMAP to deliver malicious links that harvest and exfiltrate web browser data from Ukrainian and Polish targets; it also highlights exploitation of the critical Outlook flaw CVE‑2023‑23397, references other Russian state-linked attacks (e.g., Sandworm against Kyivstar), and recommends urgent mitigations such as patching, enforcing MFA, securing RDP, and continuous third-/fourth-party risk monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.