logo

Russian military hackers target Ukraine with new MASEPIE malware

ID: cca8459c-8911-50d8-be0d-cfd77990a254

STIX ID: report--cca8459c-8911-50d8-be0d-cfd77990a254

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2023-12-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive Summary:** Ukraine's CERT warns of a December 15–25, 2023 phishing campaign attributed to APT28 that used malicious links to drop a Windows LNK that launches PowerShell to install a new Python downloader called MASEPIE, deploy PowerShell 'STEELHOOK' infostealers, and deploy an OCEANMAP C# backdoor using IMAP for stealthy C2; attackers established persistence via Startup folder and registry changes and used IMPACKET/SMBEXEC for rapid lateral movement, with tools reportedly deployed within an hour of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.