Fighting Ursa Luring Targets With Car for Sale


A Russian threat actor Palo Alto Unit 42 track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024.

Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content.

Read more…
Source: Palo Alto


Sign up for our Newsletter


Related:

  • Twitter API Abused to Uncover User Identities

    February 4, 2020

    Twitter said that malicious actors, with potential ties to state-sponsored groups, were abusing a legitimate function on its platform to unmask the identity of users. The social media giant said that on Dec. 24, 2019, it discovered a large network of fake accounts abusing a legitimate API (application programming interface) function on its platform that, when ...

  • FBI launches investigation into Pegasus spyware vendor over US citizen hacks

    January 31, 2020

    The US Federal Bureau of Investigation (FBI) has launched an investigation into NSO Group based on suspicions that US residents and companies may have been compromised for intelligence-gathering purposes. According to the Reuters news agency, investigators began examining NSO in 2017 during an inquiry into whether US hackers had provided the code necessary for the company to ...

  • Jeff Bezos hack: Amazon boss’s phone ‘hacked by Saudi crown prince’

    January 22, 2020

    The Amazon billionaire Jeff Bezos had his mobile phone “hacked” in 2018 after receiving a WhatsApp message that had apparently been sent from the personal account of the crown prince of Saudi Arabia, sources have told the Guardian. The encrypted message from the number used by Mohammed bin Salman is believed to have included a malicious file that infiltrated ...

  • US Cyber Command was not prepared to handle the amount of data it hacked from ISIS

    January 21, 2020

    Documents obtained through FOIA (Freedom of Information Act) requests and made public today reveal that while successful, the US Cyber Command’s campaign to hack ISIS faced some issues, such as lacking the storage space to store all the information stolen from ISIS accounts. The six heavily-redacted documents published today by the National Security Archive at the ...

  • Mitsubishi Electric discloses security breach, China is main suspect

    January 20, 2020

    In a short statement published today on its website, Mitsubishi Electric, one of the world’s largest electronics and electrical equipment manufacturing firms, disclosed a major security breach. Although the breach occurred last year, on June 28, and an official internal investigation began in September, the Tokyo-based corporation disclosed the security incident today, only after two local newspapers, the Asahi ...

  • New JhoneRAT Malware Targets Middle East

    January 17, 2020

    Researchers are warning of a new remote access trojan (RAT), dubbed JhoneRAT, which is being distributed as part of an active campaign, ongoing since November 2019, that targets victims in the Middle East. Once downloaded, the RAT gathers information on the victims’ computers and is also able to download additional payloads. Evidence shows that the attackers behind JhoneRAT ...