A Russian threat actor Palo Alto Unit 42 track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024.
Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content.
Read more…
Source: Palo Alto
Related:
- In line with PM Modi’s push, Army gets new software to enhance cyber security
April 2, 2017
In line with Prime Minister Narendra Modi‘s push for enhancing cyber security, the Indian Army is testing the indigenous BOSS (Bharat Operating System Solutions) to guard its communication and information networks from espionage by foreign players. In his maiden address to the senior commanders of the three services, the prime minister had asked them to guard ...
- WikiLeaks’ latest release of CIA cyber tools could blow cover on agency hacking operations
April 1, 2017
WikiLeaks’ latest disclosure of CIA cyber tools reveals a technique used by the agency to hide its digital tracks, potentially blowing the cover on current and past hacking operations aimed at gathering intelligence on terrorists and other foreign targets. The release on Friday of the CIA’s “Marble Framework” comes less than a month after the anti-secrecy ...
- Espionage Group Turla Tweaks Carbon Backdoor Malware with New Variants
March 30, 2017
Russian espionage group Turla has been working on various tools for years, including several new versions of Carbon, a second stage backdoor malware. The discovery was made by researchers from ESET who claim that this malware is still under active development. Since the group is well known for changing its tools once they are exposed, it’s ...
- Germany Fought Off Two Fancy Bear Cyber Attacks in 2016
March 27, 2017
Fears about Russian involvement in European elections, especially after last year’s US election, aren’t exactly unfounded or born out of paranoia. In fact, Germany says it fended off two cyber attacks coming from the same cybercriminals that targeted Hillary Clinton’s campaign. Arne Schoenbohm, a top German official, told Reuters they managed to fight off two attacks ...
- Treason charges against Russian cyber experts linked to seven-year-old accusation
February 26, 2017
Treason charges brought in December against two Russian state security officers and a cyber-security expert in Moscow relate to allegations made by a Russian businessman seven years ago, according to the businessman and a source connected with the investigation. They said the arrests concern allegations that the suspects passed secrets to U.S. firm Verisign and other ...
- Second FSB Agent Arrested for Treason Revealed as Notorious Hacker
January 27, 2017
Major Dmitry Dokuchaev, one of four cyber-security experts arrested by the Kremlin on charges of treason, has allegedly been revealed as an infamous Russian hacker. Dokuchaev worked as a hacker under the alias “Forb” until Russia’s Federal Security Service (FSB) threatened to jail him, an unverified source told the RBC newspaper. “Forb” gave a interview to Russian ...

