Russian APT Group Thwarted in Attack on US Automotive Manufacturer
ID: f11b3ec0-a72a-5aff-a3e8-a968e4a187e7
STIX ID: report--f11b3ec0-a72a-5aff-a3e8-a968e4a187e7
Feed Name: Dark Reading
Threat Score
FIN7 (aka Carbon Spider / ELBRUS / Sangria Tempest) conducted a spear-phishing campaign in late 2023 against a large US-based automotive manufacturer, luring high-privilege IT staff with a malicious URL masquerading as an IP scanning tool. The actors delivered the Anunak backdoor and used living-off-the-land binaries and scripts to establish footholds; BlackBerry's threat research team detected and disrupted the campaign before the ransomware stage could be executed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
