logo

Commercial Spyware Vendors Have a Copycat in Top Russian APT

ID: ff8d9eb6-f7fa-5d28-a082-15bfdd2be3df

STIX ID: report--ff8d9eb6-f7fa-5d28-a082-15bfdd2be3df

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-08-30

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Multiple watering-hole campaigns attributed to Russian-backed APT29 targeted visitors of Mongolian government websites (cabinet.gov.mn and mfa.gov.mn), delivering n-day mobile exploits—including one tracked as CVE-2023-41993—that match earlier 0-day tooling used by commercial surveillance vendors (Intellexa and NSO), suggesting reuse or shared sourcing of exploits and active in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.