The Ukrainian company CERT-UA warns of a new phishing campaign from the APT28 group, which is linked to Russia.

This activity, which occurred from December 15 to 25, 2023, targets government agencies with emails that invite recipients to click on a link that may contain malware.
Read more: CERT-UA warns of SmokeLoader and RoarBAT malware attacks against Ukraine
These links redirect to websites that exploit JavaScript and the “search-ms:” URI protocol to perform malicious actions, including PowerShell commands to create an infection chain with the MASEPIE malware.
MASEPIE is a tool used to download and upload files, as well as execute commands, by communicating with a command and control (C2) server via an encrypted TCP channel.
The attacks create the opportunity for the deployment of malware, such as STEELHOOK, which collects browsing data, as well as the OCEANMAP backdoor, which is used to execute commands via cmd.exe and the IMAP protocol as a control channel.
It was revealed that base64 encoded commands are found in the “Drafts” folder of emails, containing information about computers, users and operating system versions . The results are saved in the “Inbox” folder. The activities are carried out after negotiation, using tools such as Impacket and SMBExec.

See also: Phishing sites for product delivery services increased in December
Additionally, it was reported that the APT28 group used decoys during the war between Israel and Hamas, using a specialized portal called HeadLace. In addition, there are reports that Russian hacking groups, among others, exploited a serious security issue (CVE-2023-23397) in the Outlook email service, which is rated 9.8 on the CVSS scale, to gain unauthorized access to Exchange server accounts.
Source: thehackernews.com
