logo

Russian APT Phishes Kazakh Gov't for Strategic Intel

ID: d42c9112-e051-548f-986b-39121ad84d8b

STIX ID: report--d42c9112-e051-548f-986b-39121ad84d8b

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2025-01-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers observed a Russia-linked APT (UAC-0063, likely connected to APT28/Fancy Bear) conducting targeted spear-phishing against Kazakh diplomatic entities using malicious Word documents that prompt enabling macros; these deploy a hidden Word instance that drops an HTA backdoor named HatVibe (and has previously been used to deliver a Python backdoor called CherrySpy). Eleven realistic lure documents—draft statements, embassy letters, and administrative briefs—appear to have been used to harvest intelligence on Kazakhstan's diplomatic and economic activities, consistent with nation-state espionage objectives in Central Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.