216.73.216.6

Fighting Ursa Luring Targets With Car for Sale

· Published 05/08/2024 08:30 · Modified 05/08/2024 08:34

Export JSON

Essential information

Published
05/08/2024 08:30
Modified
05/08/2024 08:34
Tags
2024-08-05 backdoor diplomats espionage headlace malware phishing russia
Related entities
1 vulnerabilities (cve), 6 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware

Description

This analysis examines a campaign attributed to the Russian threat actor Fighting Ursa, also known as APT28, Fancy Bear, and Sofacy. The group utilized a lure disguised as an advertisement for a car sale to distribute the , likely targeting . The lure exploited legitimate services like Webhook.site and ImgBB to host various components of the attack chain. The employed multi-stage loading tactics, executing a malicious DLL through a batch script to retrieve additional payloads. The campaign aligns with Fighting Ursa's known tactics, techniques, and procedures, demonstrating the group's continued reliance on repurposing successful tactics and abusing free services.

External references