logo

Criminals, Not State Actors, Target Russian Oil Company in 3-Year Cyber Attack

ID: a57f9520-df9b-5ee0-b8bf-da357fd22ba3

STIX ID: report--a57f9520-df9b-5ee0-b8bf-da357fd22ba3

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2018-12-12

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Researchers uncovered a three-year targeted campaign against Rosneft that used macros, keyloggers, C2 domains mimicking major organizations, and fake websites to harvest credentials and conduct business email compromise (BEC). Initially resembling an APT-style espionage effort due to its targeting and techniques, analysis tied the toolset to prior criminal activity (including attacks on Steam users) and concluded the motive was financial, likely by a Russian or Eastern European criminal group employing APT-like TTPs to obfuscate attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.