logo

Russian Intelligence Targets Victims Worldwide in Rapid-Fire Cyberattacks

ID: 7dca3e48-3338-5aa4-9c4e-819141eebbe9

STIX ID: report--7dca3e48-3338-5aa4-9c4e-819141eebbe9

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-03-20

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

IBM X-Force warns that Russian APT28 (aka Fancy Bear / ITG05) is running targeted phishing campaigns across at least nine countries using government-themed lures to deliver a Python backdoor (Masepie) and secondary tools (Oceanmap, Steelhook) for reconnaissance, lateral movement, and data exfiltration; the campaign leverages known CVEs and fast post-exploitation actions, and defenders are advised to monitor FirstCloudIT-hosted URLs, suspicious IMAP traffic, NTLMv2 relay indicators, and the listed CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.