APT28 Cyber Espionage Campaign Targets French Institutions Since 2021
ID: 4ff68191-9997-518a-a8ee-ad3e258672fc
STIX ID: report--4ff68191-9997-518a-a8ee-ad3e258672fc
Feed Name: securityonline.info
ANSSI describes a sustained APT28 (Fancy Bear) espionage campaign since 2021 targeting French and European governmental, diplomatic, defence, research and industrial organizations using phishing, brute-force webmail attacks, exploitation of known vulnerabilities (e.g., CVE-2023-23397), and commodity/outsourced infrastructure (Mocky.IO, InfinityFree) to deliver malware families including HeadLace, OceanMap (an IMAP-based stealer), SteelHook and MasePie, often focused on rapid data exfiltration rather than long-term persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
