logo

Suspected APT29 Operation Launches Election Fraud Themed Phishing Campaigns

ID: 81a00f23-4ea6-5bcb-b264-1f233c17f030

STIX ID: report--81a00f23-4ea6-5bcb-b264-1f233c17f030

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2021-05-27

Date Updated: 2026-05-01

...
...

Volexity observed a USAID-themed spear-phishing campaign (May 2021) targeting NGOs, research institutions, government and international agencies in the US and Europe; recipients who clicked embedded Constant Contact links were redirected to download an ISO (ICA-declass.iso) containing a decoy PDF, a malicious LNK and Document.dll that deobfuscates and runs a Cobalt Strike HTTPS Beacon and later fetches a second-stage FRESHFIRE DLL via Firebase. The report includes detailed IOC lists (domains, IPs, Firebase paths), file hashes, YARA rules, analysis of anti-VM/sandbox checks, Cobalt Strike configuration and attribution to APT29 with moderate confidence, and recommends blocking identified indicators and deploying the provided detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.