A group of hackers that has often been linked by researchers to the Kremlin have now changed their tactics when it comes to attacks against the United States (US) government.
A new attack using the new tactic of these hackers occurred just a few days ago.
Specifically, a phishing email from the Sofacy group (also known as APT28) was sent to a United States (US) government agency from a possibly compromised account belonging to the Department of State, which email was described as another “government agency” and was sent baited with the Carberp variant of the Sofacy Trojan.
“The threat actors added a new and persistent mechanism to the Trojan, which had never been seen in any of the previous attacks,” according to Palo Alto Networks security researchers from the Unit 42 threat intelligence group.
“ This new variant definitely requires user interaction, i.e. loading its paid payload into Microsoft Office applications when they are opened, thus helping the actors evade detection.”

More details about the hackers' new attack and their new tactics can be found in the relevant blog post posted by Palo Alto Networks by simply clicking here to follow the link.
APT28 has been accused many times in the past of attacks against Georgia, against governments in Eastern Europe, as well as against NATO and the Organization for Security and Cooperation in Europe.
