logo

RDoS attacks by fake Fancy Bear hit banks in multiple locations

ID: 8a68b753-ec05-5e9a-b9a8-f8def8b5fe84

STIX ID: report--8a68b753-ec05-5e9a-b9a8-f8def8b5fe84

Feed Name: Group-IB Blog

Threat Score
45/100

Date Published: 2019-11-05

Date Updated: 2026-04-27

...
...

In late October 2019 a mass email extortion (RDoS) campaign targeted banks and financial organizations across multiple regions, impersonating Fancy Bear to demand 3 BTC and threatening DDoS attacks; some recipients saw small demonstration UDP/ICMP floods (including use of UDP port 3283). Group-IB concludes the activity was financially motivated extortion by impostors rather than the real APT28, and highlights indicators such as the sender [email protected] and the novel use of ARD-related UDP port 3283 in DDoS traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.