"APT28 Hacker Group's Global Phishing Campaign Exposed"

1 min read
Source: The Hacker News
"APT28 Hacker Group's Global Phishing Campaign Exposed"
Photo: The Hacker News
TL;DR Summary

APT28, a Russia-linked threat actor, has been conducting widespread phishing campaigns targeting organizations in Europe, the Americas, and Asia by using lure documents imitating government and non-governmental entities. The group, also known as ITG05, has been deploying various malware such as MASEPIE, OCEANMAP, and STEELHOOK to exfiltrate files, run arbitrary commands, and steal browser data. They have been leveraging security flaws in Microsoft Outlook and the "search-ms:" URI protocol handler in Microsoft Windows to trick victims into downloading malware. Additionally, they have been using compromised Ubiquiti routers to host their servers. The phishing attacks impersonate entities from multiple countries and utilize a mix of authentic publicly available government and non-government lure documents to activate the infection chains.

Share this article

Reading Insights

Total Reads

0

Unique Readers

2

Time Saved

2 min

vs 3 min read

Condensed

74%

450117 words

Want the full story? Read the original article

Read on The Hacker News