A large-scale cyberespionage campaign has been targeting organizations in the renewable energy and industrial technology sectors 2019.since According to the researcher who discovered the campaign, more than fifteen entities around the world have been targeted.
See also: Phishing attacks: Which major companies do scammers imitate to trick victims?

The cyberespionage campaign was discovered by security researcher William Thomas, a member of Curated Intelligence, who used OSINT (open-source intelligence) techniques, such as DNS scans and public sandbox submissions.
According to Thomas, the attackers are using a custom 'Mail Box' toolkit, a not-so-sophisticated phishing package deployed on the criminals' infrastructure, as well as legitimate websites that have been compromised to host phishing pages.
Most phishing pages were hosted on “*.eu3[.]biz”, “*.eu3[.]org”, and “*.eu5[.]net” domains, while the majority of compromised sites are located in Brazil (“*.com[.]br”).
See also: Nintendo: Fake sites claim to be selling Nintendo Switch at a low price
Cyber espionage campaign targets renewable energy sector
The goal of the phishing campaign is to steal the credentials of people working in the renewable energy sector, environmental protection organizations, and generally companies related to industrial technology.

Some of the goals:
- Schneider Electric
- Honeywell
- Huawei
- HiSilicon
- Telekom Romania
- University of Wisconsin
- California State University
- Utah State University
- Kardzhali Hydroelectric Power Station (Bulgaria)
- CEZ Electro (Bulgaria)
- California Air Resources Board
- Morris County Municipal Utilities Authority
- Taiwan Forestry Research Institute
- Carbon Disclosure Program
- Sorema (Italian recycling company)
The researcher does not have samples of the phishing emails sent as part of the cyber espionage campaign. However, he believes the subject of the email was: “Your Mail Box storage is full.”
See also: Russia: Charges 8 gang members suspected of REvil ransomware
Furthermore, the campaign has not been linked to any specific hacking group, although some evidence suggests similarities to the modus operandi of APT28 (also known as FancyBear) and Konni (hackers from North Korea). However, these are mere assumptions.
Researchers from Google's Threat Analysis Team recently discovered phishing activity attributed to APT28, which uses several “eu3[.]biz” domains.
Source: Bleeping Computer
