APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme
ID: 05d9fb5d-fd8f-5870-b080-38198ae904e0
STIX ID: report--05d9fb5d-fd8f-5870-b080-38198ae904e0
Feed Name: The Hacker News
IBM X-Force attributes a series of ongoing phishing campaigns across Europe, the South Caucasus, Central Asia, and the Americas to Russia-linked APT28 (ITG05), which use authentic-looking lure documents to deliver custom implants and information stealers (MASEPIE, OCEANMAP, STEELHOOK, HeadLace). The actor leverages techniques including the Windows "search-ms:" URI handler and exploitation of CVE-2023-23397 to harvest NTLMv2 hashes, stages payloads on actor-controlled WebDAV and commercial hosting (firstcloudit.com), and may be leveraging compromised Ubiquiti routers for C2 and payload hosting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
