• contact@globalcase.org
  • +995322476006
ქართული
  • About UsAbout Us
    • About CASEAbout CASE
    • Our teamour-team
    • CASE AnalyticsCASE Analytics
    • CASE NetworkingCASE Networking
    • Careercareer
    • Certificationcertification
    • Cyber Security in CASECyber Security in CASE
    • Success StoriesSuccess Stories
    • Contact UsGet in touch
  • Blog
  • ServicesServices
    • Personal Data ProtectionPersonal Data Protection Service and DPO Outsourcing
    • Cyber Security ServicesCyber Security Services
    • Corporate TrainingsCorporate Trainings
  • HomeLets start here
  • Mediamedia
    • Media about usMedia about us
    • News
  • CoursesCourses
  • Resources
    • Cyber PodcastCyber Podcast
    • Research and Analysis
    • E-Books
    • Security Brief
    • Frequently asked QuestionsFrequently asked Questions
logo
CASE

Email Address

contact@globalcase.org

Phone

+995322476006
  • About UsAbout Us
    • About CASEAbout CASE
    • Our teamour-team
    • CASE AnalyticsCASE Analytics
    • CASE NetworkingCASE Networking
    • Careercareer
    • Certificationcertification
    • Cyber Security in CASECyber Security in CASE
    • Success StoriesSuccess Stories
    • Contact UsGet in touch
  • Blog
  • ServicesServices
    • Personal Data ProtectionPersonal Data Protection Service and DPO Outsourcing
    • Cyber Security ServicesCyber Security Services
    • Corporate TrainingsCorporate Trainings
  • HomeLets start here
  • Mediamedia
    • Media about usMedia about us
    • News
  • CoursesCourses
  • Resources
    • Cyber PodcastCyber Podcast
    • Research and Analysis
    • E-Books
    • Security Brief
    • Frequently asked QuestionsFrequently asked Questions

Security Brief

    HomeSecurity Brief
    Russian Hacker Group Linked To Major Global Phishing Scheme
Russian Hacker Group Linked To Major Global Phishing Scheme
Russian Hacker Group Linked To Major Global Phishing Scheme
In:
Breaking News
Created:
18 Mar 2024
Share :

APT28, a hacker entity with ties to Russia better known by the moniker Fancy Bear, has been connected to several active phishing attempts that use sham papers that purport to be from governments and non-governmental organizations (NGOs) across North and South America, Europe, South Caucasus & Central Asia.

The information was made public over three months after it was discovered that the enemy was deploying HeadLace, a specially designed backdoor, through ruses associated with the current Israel-Hamas conflict.

Since then, APT28 has also sent phishing messages to Polish and Ukrainian government institutions in PDF formats with the intention of deploying specialized implants and information thieves such as MASEPIE, OCEANMAP, and STEELHOOK.

The PDFs contain URLs that point to infected websites that have the ability to misuse both the "search:" application protocol and the "search-ms:" URI handler. While the protocol acts as a means of contacting Windows' desktop search program, the handler enables apps and HTML links to initiate personalized local searches on a device.

Consequently, the victims find themselves conducting searches on a server under the control of the attacker and encountering malware displayed in Windows Explorer. The victims are encouraged to download and execute this malware, which is disguising itself as a PDF file.

Although the victims' identities are unknown, it is reasonable to believe that they are citizens of the same nations as the governments and non-governmental organizations that are the targets of the attacks: Georgia, Argentina, Ukraine, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the United States.

In:
Breaking News

Search Date

Categories

  • Breaking News
  • Updates
  • Thoughts
  • footer_logo

    Advancing Security as a Profession!

    Join Newsletter

    Services

    • Cyber and Information Security
    • Bank Security officer course
    • Work safety services
    • Fire safety training
    • First aid training

    Links

    • FAQ
    • Services
    • Courses
    • Privacy Policy
    • Terms

    Contact

    • +995 322 476 006
    • contact@globalcase.org
    • Georgia, Tbilisi, Pekini Ave. 30
    • Homepage
    • Main competence
    • Services
    • Courses
    • Blog
    • Contact us