Russia's 'Fancy Bear' APT Continues Its Global Onslaught
ID: a3e3655c-ea57-51a6-9a4f-6f307779606f
STIX ID: report--a3e3655c-ea57-51a6-9a4f-6f307779606f
Feed Name: Dark Reading
Trend Micro and government reporting detail active operations by Fancy Bear (APT28/Pawn Storm) targeting defense and government supply chains using a Prismex malware suite (including steganography, COM hijacking, cloud abuse and wiper capabilities), NTLMv2 relay attacks exploiting CVE-2023-23397, and router-based DNS hijacking via CVE-2023-50224; the coverage includes observed targets, timelines (2022–2025+), and mitigation advice such as patching, MFA, router firmware updates, and zero trust controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
