Russian Intelligence Targets Victims Worldwide in Rapid-Fire Cyberattacks
ID: 7dca3e48-3338-5aa4-9c4e-819141eebbe9
STIX ID: report--7dca3e48-3338-5aa4-9c4e-819141eebbe9
Feed Name: Dark Reading
IBM X-Force warns that Russian APT28 (aka Fancy Bear / ITG05) is running targeted phishing campaigns across at least nine countries using government-themed lures to deliver a Python backdoor (Masepie) and secondary tools (Oceanmap, Steelhook) for reconnaissance, lateral movement, and data exfiltration; the campaign leverages known CVEs and fast post-exploitation actions, and defenders are advised to monitor FirstCloudIT-hosted URLs, suspicious IMAP traffic, NTLMv2 relay indicators, and the listed CVEs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
