logo

Russia's 'Fighting Ursa' APT Uses Car Ads to Install HeadLace Malware

ID: 616207b3-db3a-5c8b-be5e-c36969f212ed

STIX ID: report--616207b3-db3a-5c8b-be5e-c36969f212ed

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-08-05

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

A Russian APT known as Fighting Ursa (APT28/Fancy Bear) targeted diplomats with a used-car sale phishing scheme that hosts a malicious HTML on webhook services and offers a ZIP containing disguised executables; the embedded DLL and scripts deploy the HeadLace backdoor to establish persistent access for espionage. Unit 42 links these TTPs to prior Fighting Ursa campaigns and highlights use of freely available hosting, hidden .exe extensions, and decoy images to increase click-through and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.