Russian military hackers target Ukraine with new MASEPIE malware
ID: cca8459c-8911-50d8-be0d-cfd77990a254
STIX ID: report--cca8459c-8911-50d8-be0d-cfd77990a254
Feed Name: Bleeping Computer
**Executive Summary:** Ukraine's CERT warns of a December 15–25, 2023 phishing campaign attributed to APT28 that used malicious links to drop a Windows LNK that launches PowerShell to install a new Python downloader called MASEPIE, deploy PowerShell 'STEELHOOK' infostealers, and deploy an OCEANMAP C# backdoor using IMAP for stealthy C2; attackers established persistence via Startup folder and registry changes and used IMPACKET/SMBEXEC for rapid lateral movement, with tools reportedly deployed within an hour of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
