Threat Advisory

Suspected Russian Activity Targeting Government and Business Entities Around the Globe

Threat: APT
Criticality: High
[subscribe_to_unlock_form]

Summary:

APT29 Threat Actor also known as CozyBear is attributed to Russia's Foreign Intelligence Service which is operational since at least 2008. Often seen targeting government organizations in Europe, the Middle East, Asia, NATO member countries, research institutes, and think tanks. Recently, Researchers have discovered a new Espionage campaign where the groups are trying to steal data relevant to Russian interests. The APT group in the said campaign was compromising companies from the government sector by means of using credentials harvested from third-party campaigns. They were using TTPs to bypass security solutions and a new downloader named CEELOADER and CRYPTBOT, and frameworks like Cobalt Strike. They were also abusing MFA (Multi-factor authentication).[/subscribe_to_unlock_form]

Summary:

APT29 Threat Actor also known as CozyBear is attributed to Russia's Foreign Intelligence Service which is operational since at least 2008. Often seen targeting government organizations in Europe, the Middle East, Asia, NATO member countries, research institutes, and think tanks. Recently, Researchers have discovered a new Espionage campaign where the groups are trying to steal data relevant to Russian interests. The APT group in the said campaign was compromising companies from the government sector by means of using credentials harvested from third-party campaigns. They were using TTPs to bypass security solutions and a new downloader named CEELOADER and CRYPTBOT, and frameworks like Cobalt Strike. They were also abusing MFA (Multi-factor authentication).[emaillocker id="1283"]

Threat Profile:

References:

The following reports contain further technical details:

https://www.mandiant.com/resources/blog/russian-targeting-gov-business

[/emaillocker]
crossmenu