Kremlin-Backed APT28 Targets Polish Institutions in Large-Scale Malware Campaign
ID: de721656-6440-5e00-bd3f-85672c404718
STIX ID: report--de721656-6440-5e00-bd3f-85672c404718
Feed Name: The Hacker News
Threat Score
**Executive summary:** APT28 (Russia-linked) is conducting a phishing-driven malware campaign against Polish government entities, abusing run.mocky.io and webhook.site to deliver a ZIP containing a masqueraded Windows binary, a hidden batch script, and a DLL (WindowsCodecs.dll) that is side-loaded to execute a payload which gathers and exfiltrates information; CERT Polska recommends blocking or filtering the noted domains and links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
