TURLA’s New Phishing Campaign in Eastern Europe
ID: c6f4c33f-6c88-50c0-84e1-3dfde9c8aa29
STIX ID: report--c6f4c33f-6c88-50c0-84e1-3dfde9c8aa29
Feed Name: Sekoia.com
Sekoia TDR expanded on Google's TAG findings and identified a Turla (Russian-linked) reconnaissance and espionage campaign targeting the Baltic Defense College, the Austrian Federal Economic Chamber, and NATO's JDAL via typosquatted domains and weaponized DOCX files that load an external PNG. The remote image request allowed the actor to fingerprint Word versions and capture victim IPs; the report provides infrastructure IoCs (IPs and domains), document hashes, a YARA rule, and ATT&CK technique mappings attributed to TURLA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
