216.73.216.226

Hunting Laundry Bear: Infrastructure Analysis Guide and Findings

· Published 29/08/2025 12:19 · Modified 29/08/2025 15:19

Export JSON

Essential information

Published
29/08/2025 12:19
Modified
29/08/2025 15:19
Tags
2025-08-29 apt domain typosquatting infrastructure analysis nato targets russian threat actor spear-phishing ukraine targets
Related entities
1 intrusion sets (apt), 1 techniques (mitre), 6 others

Description

This analysis explores the infrastructure of Laundry Bear, a Russian state-sponsored group active since April 2024, targeting NATO countries and Ukraine. The investigation expands on initial indicators, using advanced pivoting techniques to uncover additional domains and infrastructure. Key findings include the discovery of multiple lookalike domains, similar registration patterns, and shared hosting infrastructure. The analysis reveals a network of domains with login and account management themes, redirecting to legitimate Microsoft services. The investigation also uncovers connections to other potential malicious activities, including attempts and the use of PDF files for possible malware delivery. The findings demonstrate the extensive infrastructure used by the threat actor and highlight the importance of advanced threat hunting techniques in uncovering related malicious activities.

External references