A Russian threat actor Palo Alto Unit 42 track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024.
Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content.
Read more…
Source: Palo Alto
Related:
- WhatsApp spy mod spreads through Telegram, attacks Arabic-speaking users
November 2, 2023
It is not rare that users of popular instant messaging services find the official client apps to be lacking in functionality. To address that problem, third-party developers come up with mods that offer sought-after features besides aesthetic upgrades. Unfortunately, some of these mods contain malware alongside legitimate enhancements. A case in point occurred last year ...
- Over the Kazuar’s nest: Cracking down on a freshly hatched backdoor used by Pensive Ursa
October 31, 2023
While tracking the evolution of Pensive Ursa (aka Turla, Uroburos), Unit 42 researchers came across a new, upgraded variant of Kazuar. Not only is Kazuar another name for the enormous and dangerous cassowary bird, Kazuar is an advanced and stealthy .NET backdoor that Pensive Ursa usually uses as a second stage payload. Pensive Ursa is a ...
- From Albania to the Middle East: The Scarred Manticore is listening
October 31, 2023
Check Point Research, in collaboration with Sygnia’s Incident Response Team, has been tracking and responding to the activities of Scarred Manticore, an Iranian nation-state threat actor that primarily targets government and telecommunication sectors in the Middle East. Scarred Manticore, linked to the prolific Iranian actor OilRig (a.k.a APT34, EUROPIUM, Hazel Sandstorm), has persistently pursued high-profile organizations, ...
- Canada bans Chinese app WeChat from government devices
October 30, 2023
Canada has announced it will ban WeChat on government devices. The Chinese-owned app is sometimes referred to as the “everything app” – like WhatsApp, Facebook, Amazon and Tinder all in one. However Western governments have security concerns about it, mainly that the app could be used to spy on users. WeChat is one of the most ...
- The outstanding stealth of Operation Triangulation
October 23, 2023
In the previous blogpost on Triangulation, Kaspersky researchers discussed the details of TriangleDB, the main implant used in this campaign, its C2 protocol and the commands it can receive. The researchers mentioned, among other things, that it is able to execute additional modules. They also mentioned that this operation was quite stealthy. This article details ...
- Irish-linked spyware used in brazen attacks
October 21, 2023
The Irish government is set to investigate a digital surveillance alliance that has been accused of letting its smartphone spyware “run wild across the world”, BBC News NI understands. It comes after Intellexa Limited and its parent company Thalestris were named in a damning report by a leading human rights body. The firms are registered at ...
