New Malware Attributed to Russian Hacking Group APT28
ID: 8beca94f-6404-5590-bf8e-c8a94ca90522
STIX ID: report--8beca94f-6404-5590-bf8e-c8a94ca90522
Feed Name: SecurityScorecard Blog
This report summarizes CERT‑UA and SecurityScorecard findings that APT28 (Fancy Bear) has been using a new backdoor called OCEANMAP to deliver malicious links that harvest and exfiltrate web browser data from Ukrainian and Polish targets; it also highlights exploitation of the critical Outlook flaw CVE‑2023‑23397, references other Russian state-linked attacks (e.g., Sandworm against Kyivstar), and recommends urgent mitigations such as patching, enforcing MFA, securing RDP, and continuous third-/fourth-party risk monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
