logo

CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK

ID: 47b9de0b-ec59-5d9f-923d-91b81c9606da

STIX ID: report--47b9de0b-ec59-5d9f-923d-91b81c9606da

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2023-12-29

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

CERT-UA reported a December 15–25, 2023 phishing campaign attributed to APT28 that used malicious links abusing the search-ms: URI to drop Windows LNK files which launch PowerShell to install a Python-based backdoor (MASEPIE), a PowerShell-based browser-data harvester (STEELHOOK), and a C# backdoor (OCEANMAP). The actors used IMAP as a control channel with Base64-encoded commands stored in email drafts, achieved persistence via a VMSearch.url placed in Startup, and performed rapid reconnaissance and lateral movement using tools like Impacket and SMBExec.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.