CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
ID: 47b9de0b-ec59-5d9f-923d-91b81c9606da
STIX ID: report--47b9de0b-ec59-5d9f-923d-91b81c9606da
Feed Name: The Hacker News
CERT-UA reported a December 15–25, 2023 phishing campaign attributed to APT28 that used malicious links abusing the search-ms: URI to drop Windows LNK files which launch PowerShell to install a Python-based backdoor (MASEPIE), a PowerShell-based browser-data harvester (STEELHOOK), and a C# backdoor (OCEANMAP). The actors used IMAP as a control channel with Base64-encoded commands stored in email drafts, achieved persistence via a VMSearch.url placed in Startup, and performed rapid reconnaissance and lateral movement using tools like Impacket and SMBExec.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
