Russian hackers “APT29”, also known as Nobelium or Cloaked Ursa, are using unusual tricks to trick diplomats in Ukraine. For example, they are using car ads as a lureto get them to click on malicious links and download malware.

APT29 is affiliated with the Foreign Intelligence Service (SVR) and has been linked to multiple cyberespionage campaigns.
Over the past two years, Russian hackers have targeted members of NATO, the EU, and Ukraine, using phishing emails and documents that are usually about foreign policy. The emails contain fake websites to infect their targets with backdoors.
See also: SonicWall: Warns of critical vulnerabilities
Palo Alto Networks' Unit 42 team says in a new report that APT29 is evolving its phishing tactics , using more personal lures for recipients.
Luxury car advertisement in Kyiv
Unit 42 reported a recent APT29 operation that began in May 2023. The perpetrators used an advertisement for BMW cars to target diplomats in Kiev, Ukraine.
An advertisement for the sale of the car was sent to email .
When recipients click on the “more high-quality photos” link embedded in the malicious document, they are redirected to an HTML page that delivers malicious ISO file payloads via HTML smuggling.
See also: Fortinet warns of critical RCE bug in FortiOS, FortiProxy devices
HTML smuggling is a technique often used in phishing campaigns and helps avoid detection by security, as the malicious code is disguised and decoded only when rendered in the browser.
The ISO file contains nine PNG images, but they are actually LNK files that trigger the infection chain.

When the victim opens any of the LNK files presented as PNG images, it launches a legitimate executable file that uses DLL side-loading to inject shellcode into the current process in memory.
Unit 42 says this campaign has targeted at least 22 of the 80 foreign missions in Kiev, including those from the United States, Canada, Turkey, Spain, the Netherlands, Greece, Estonia, and Denmark. However, it is not known exactly how many diplomats have been affected.
Another recent attack by APT29 hackers involved a PDF sent to the Turkish Ministry of Foreign Affairs (MFA) earlier in 2023, and had as its subject “humanitarian aid for the earthquake” that hit Turkey in February.
See also: Bangkok Post hit by ransomware attack
According to Unit 42, the malicious PDF was likely shared among Ministry employees and forwarded to other Turkish organizations.
As the situation between Ukraine and Russia continues to be explosive, it is expected that Russian hacking groups will continue to intensify their efforts to target diplomatic missions.
Phishing attacks constitute a continuous threat to online security, but with a little knowledge and effort, you can protect yourself from these attacks. Always be cautious about any unwanted messages and verify the authenticity of messages and links before clicking on them. Use security measures such as antivirus protection and two-factor authentication to protect your data from theft.
Source: www.bleepingcomputer.com
