Security Snippets: Espionage group expands global phishing campaign

Hogan Lovells
Contact

Hogan Lovells

Russia-linked threat actor Fancy Bear is conducting a wave of phishing campaigns impersonating entities across Europe, Americas, and Asia, focusing on Ukraine-related targets.


IBM X-Force has identified an ongoing phishing campaign conducted by ITG05, a Russia state-sponsored group also known as “Fancy Bear,” which involves the use of documents designed to impersonate government and non-governmental organizations in Ukraine, Georgia, Kazakhstan, Belarus, Argentina, and the United States. The identified documents have been comprised of both internal and publicly available documents relating to a variety of topics including finance, critical infrastructure, cyber security, healthcare, business, and executive engagements.

The latest phishing attacks appear to be part of a continuous effort by Fancy Bear to deceive victims in, or with a connection to, Ukraine into downloading malicious software leveraging the “search-ms” protocol and WebDAV servers. Similar to Fancy Bear’s previous activities, the end goal of this scheme is to enable the group to steal files, execute arbitrary commands, and pilfer sensitive data from web browsers. It is likely that Fancy Bear will continue to leverage commercially available infrastructure and deploy new infection methodologies to achieve its goals.

Companies with business or operations in Ukraine, or who are otherwise likely to be on the radar of the Russian government, may want to consider issuing a phishing reminder specifically noting the potential for threat actors to provide what look like official governmental documents.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Hogan Lovells | Attorney Advertising

Written by:

Hogan Lovells
Contact
more
less

Hogan Lovells on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide