Russian APT Phishes Kazakh Gov't for Strategic Intel
ID: d42c9112-e051-548f-986b-39121ad84d8b
STIX ID: report--d42c9112-e051-548f-986b-39121ad84d8b
Feed Name: Dark Reading
Researchers observed a Russia-linked APT (UAC-0063, likely connected to APT28/Fancy Bear) conducting targeted spear-phishing against Kazakh diplomatic entities using malicious Word documents that prompt enabling macros; these deploy a hidden Word instance that drops an HTA backdoor named HatVibe (and has previously been used to deliver a Python backdoor called CherrySpy). Eleven realistic lure documents—draft statements, embassy letters, and administrative briefs—appear to have been used to harvest intelligence on Kazakhstan's diplomatic and economic activities, consistent with nation-state espionage objectives in Central Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
