APT28 leverages multiple phishing techniques to target Ukrainian civil society
ID: 3badca15-33b5-5bae-9dc1-1572a796ec84
STIX ID: report--3badca15-33b5-5bae-9dc1-1572a796ec84
Feed Name: Sekoia.com
Sekoia.io documents APT28 spear-phishing against Ukrainian civil society using multiple techniques: embedded HTML attachments employing a browser-in-the-browser fake login, public webhook services (Pipedream/Webhook.site) to capture credentials, and compromised Ubiquiti routers hosting Python scripts that bypass UKR.NET 2FA, enable IMAP access, and automate mail exfiltration. The report includes malicious domains, compromised router IPs, SSH rootkit indicators, and YARA rules to detect the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
