logo

Kremlin-Backed APT28 Targets Polish Institutions in Large-Scale Malware Campaign

ID: de721656-6440-5e00-bd3f-85672c404718

STIX ID: report--de721656-6440-5e00-bd3f-85672c404718

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-05-09

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** APT28 (Russia-linked) is conducting a phishing-driven malware campaign against Polish government entities, abusing run.mocky.io and webhook.site to deliver a ZIP containing a masqueraded Windows binary, a hidden batch script, and a DLL (WindowsCodecs.dll) that is side-loaded to execute a payload which gathers and exfiltrates information; CERT Polska recommends blocking or filtering the noted domains and links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.