Poland says Russian military hackers target its govt networks
ID: ab396648-8a57-5e75-b32a-b0d05756bd7f
STIX ID: report--ab396648-8a57-5e75-b32a-b0d05756bd7f
Feed Name: Bleeping Computer
Poland's CSIRT MON and CERT Polska reported an APT28 (GRU-linked) phishing campaign targeting multiple Polish government institutions that used socially engineered lures to deliver a ZIP archive containing a camouflaged executable, hidden DLL and BAT scripts; the payload uses DLL side-loading and scripts to display a decoy image while collecting system information and communicating with a C2. The activity mirrors previous APT28 operations and references related exploitation of CVE-2023-23397 in other campaigns targeting NATO and European organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
