Criminals, Not State Actors, Target Russian Oil Company in 3-Year Cyber Attack
ID: a57f9520-df9b-5ee0-b8bf-da357fd22ba3
STIX ID: report--a57f9520-df9b-5ee0-b8bf-da357fd22ba3
Feed Name: Security Ledger
Researchers uncovered a three-year targeted campaign against Rosneft that used macros, keyloggers, C2 domains mimicking major organizations, and fake websites to harvest credentials and conduct business email compromise (BEC). Initially resembling an APT-style espionage effort due to its targeting and techniques, analysis tied the toolset to prior criminal activity (including attacks on Steam users) and concluded the motive was financial, likely by a Russian or Eastern European criminal group employing APT-like TTPs to obfuscate attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
