Threat Advisory

Bears APT Campaign Targets Critics of the Russian Government

Threat: Phishing Campaign
Criticality: High
[subscribe_to_unlock_form]

Summary:

Research has uncovered a spear-phishing campaign Russian APT group. The campaign targets entities critical of the Russian government and supportive of dissident movements, both within and outside of Russia. This campaign has been observed in multiple countries worldwide, indicating a significant and widespread threat.[/subscribe_to_unlock_form]

Summary:

Research has uncovered a spear-phishing campaign Russian APT group. The campaign targets entities critical of the Russian government and supportive of dissident movements, both within and outside of Russia. This campaign has been observed in multiple countries worldwide, indicating a significant and widespread threat.[emaillocker id="1283"]

The initial stage of the attack involves sending a spear-phishing email with a ZIP file attachment named "NASA_Job_Offer(2).zip." Inside the ZIP file is a single LNK file disguised as a PDF titled "Offer.pdf." Upon execution, a PowerShell script is triggered, which searches for a specific string pattern within the LNK file. Once found, the PowerShell script decodes the Base64 command and executes it. This command belongs to an open-source project called HTTP-Shell, which is a multiplatform reverse shell that operates over HTTP. The shell allows for various capabilities, including uploading and downloading files, auto-reconnecting to the command and control (C&C) server, and navigating directories.

Additionally, researchers have identified several other lures used in related campaigns, including a fake USAID document, an article about a Russian businessman accused of fraud, articles from media outlets critical of the Russian government, and a socio-political publication critical of the Russian government's handling of the Ukraine war. These lures all lead to the same C&C server, indicating a coordinated and targeted effort by the threat actor.

The discovery of this spear-phishing campaign highlights the ongoing threat posed by Russian APT groups targeting entities critical of the Russian government. The use of sophisticated techniques, such as disguising malicious files as legitimate documents and employing open-source tools for remote control, demonstrates the evolving tactics of these threat actors. Organizations and individuals must remain vigilant against such attacks and implement robust cybersecurity measures to mitigate the risk of compromise.

Threat Profile:

 

 

References:

Eventus Security Threat Research & Development Team

[/emaillocker]
crossmenu