logo

APT28 leverages multiple phishing techniques to target Ukrainian civil society

ID: 3badca15-33b5-5bae-9dc1-1572a796ec84

STIX ID: report--3badca15-33b5-5bae-9dc1-1572a796ec84

Feed Name: Sekoia.com

Threat Score
88/100

Date Published: 2023-05-17

Date Updated: 2026-07-20

...
...

Sekoia.io documents APT28 spear-phishing against Ukrainian civil society using multiple techniques: embedded HTML attachments employing a browser-in-the-browser fake login, public webhook services (Pipedream/Webhook.site) to capture credentials, and compromised Ubiquiti routers hosting Python scripts that bypass UKR.NET 2FA, enable IMAP access, and automate mail exfiltration. The report includes malicious domains, compromised router IPs, SSH rootkit indicators, and YARA rules to detect the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.