Hackers Target Russian Agencies With Phishing Emails

Share post:

Analysts from the Malwarebytes Threat Intelligence team have uncovered a phishing email targeting Russian government agencies. The phishing email disguise as a Windows security update to lure users to install remote access malware.

The attacks were linked to the APT group, which is believed to operate from China. The group has been linked to four separate spear-phishing campaigns, in all four cases the ultimate goal of the campaigns was to infect the targets with a custom remote access trojan (RAT).

The first of the four phishing campaigns began in February 2022, days after Russia invaded Ukraine, and the group distributed the RAT under the name “interactive_map _UA.exe.”

In the second wave of attacks, the group used a tar.gz archive intended to fix the Log4Shell vulnerability sent by the Ministry of Digital Development, Telecommunications and Mass Communications of the Russian Federation.

The third wave spoofs Rostec, a Russian state-owned defense conglomerate, and the actors use newly registered domains like “Rostec.digital” and fake Facebook accounts to spread their malware while disguising its source.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 10, 2024 – Patches for F5’s Next Central Manager released, Dell discovers data theft covering millions, and more

Patches for F5's Next Central Manager are released, Dell discovers data theft covering millions of buyers, and more Welcome...

Elon Musk’s Neuralink has issues with first human implant

Neuralink, the neurotechnology company founded by Elon Musk, has reported an issue with its first human brain implant,...

Cyber Security Today, May 8, 2024 – The alleged LockBit ransomware leader is identified, and the gang makes false claims of new victims

The alleged LockBit ransomware leader is identified, and the gang makes false claims of new victims. Welcome to Cyber...

Microsoft Ties Executive Pay to Security Performance to Boost Cybersecurity Focus

Microsoft is reported to be tying executive compensation to its security performance, signalling a serious commitment to addressing...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways