216.73.217.22

Targeted attacks leverage accounts on popular online platforms as C2 servers

· Published 30/07/2025 14:41 · Modified 30/07/2025 14:52

Export JSON

Essential information

Published
30/07/2025 14:41
Modified
30/07/2025 14:52
Tags
2025-07-30 api obfuscation c2 communication cobalt strike cobalt strike beacon dll hijacking shellcode social media spear-phishing targeted attacks
Related entities
2 observables, 1 techniques (mitre), 1 malware, 7 others

Description

A sophisticated cyberattack campaign targeted the Russian IT industry and other entities globally in late 2024. The attackers used profiles and popular websites to deliver payload information, bypassing detection methods. They employed spear phishing emails with malicious RAR archives, exploiting techniques to deploy . The campaign used profiles on GitHub, Microsoft Learn Challenge, Quora, and Russian social networks to conceal activities. The attacks primarily focused on Russian companies but also affected organizations in China, Japan, Malaysia, and Peru. The complexity of the methods used highlights the evolving tactics of threat actors in concealing well-known tools and emphasizes the need for robust cybersecurity measures.

External references