Ukraine Military Targeted With Russian APT PowerShell Attack
ID: 72432719-69c0-5d2a-a52b-a3288f569563
STIX ID: report--72432719-69c0-5d2a-a52b-a3288f569563
Feed Name: Dark Reading
A Russian APT linked to Shuckworm/STEADY#URSA has launched a targeted campaign against the Ukrainian military using a newly observed SUBTLE-PAWS PowerShell backdoor distributed via phishing-compressed archives and removable USB drives; the malware uses off-disk PowerShell stagers, registry-based persistence, multiple obfuscation methods (Base64, XOR, encoding/splitting), and adaptive C2 via Telegram, DNS and HTTP. Securonix highlights the campaign's evasive TTPs and recommends mitigations including user education, strict USB/device control policies, Sysmon and PowerShell logging, application whitelisting, enhanced email filtering, and EDR solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
