Espionage campaign linked to Russian intelligence services - Baza wiedzy - Portal Gov.pl
Tags
country: | Russia |
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Html Smuggling - T1027.006 Javascript - T1059.007 Malicious File - T1204.002 Malware - T1587.001 Malware - T1588.001 Phishing - T1660 Phishing - T1566 Server - T1583.004 Server - T1584.004 Software - T1592.002 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | 37f1fbce-d168-4e6e-a75f-86bacb2937c0 |
Fingerprint | 2504a8331035cfa9 |
Analysis status | DONE |
Considered CTI value | 1 |
Text language | |
Published | April 13, 2023, midnight |
Added to db | Aug. 15, 2023, 11:26 a.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | gov.pl gov.pl Serwis Rzeczypospolitej Polskiej |
Title | Espionage campaign linked to Russian intelligence services - Baza wiedzy - Portal Gov.pl |
Detected Hints/Tags/Attributes | 60/3/27 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 16 | gov.pl |
|
Details | Domain | 101 | cert.pl |
|
Details | Domain | 182 | www.mandiant.com |
|
Details | Domain | 36 | media.defense.gov |
|
Details | Domain | 98 | www.ncsc.gov.uk |
|
Details | Domain | 4 | www.notion.so |
|
Details | Domain | 47 | go.recordedfuture.com |
|
Details | File | 40 | gov.pl |
|
Details | File | 99 | cert.pl |
|
Details | File | 1 | csa_svr_targets_us_allies_uoo13234021.pdf |
|
Details | File | 1 | actors.pdf |
|
Details | File | 3 | cta-2023-0127.pdf |
|
Details | Mandiant Uncategorized Groups | 97 | UNC2452 |
|
Details | Threat Actor Identifier - APT | 665 | APT29 |
|
Details | Url | 2 | https://www.mandiant.com/resources/blog/unc2452-merged-into-apt29 |
|
Details | Url | 2 | https://www.microsoft.com/en-us/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium |
|
Details | Url | 1 | https://www.microsoft.com/en-us/security/blog/2021/05/28/breaking-down-nobeliums-latest-early-stage-toolset |
|
Details | Url | 2 | https://www.mandiant.com/resources/blog/tracking-apt29-phishing-campaigns |
|
Details | Url | 1 | https://www.microsoft.com/en-us/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/. |
|
Details | Url | 1 | https://media.defense.gov/2021/apr/15/2002621240/-1/-1/0/csa_svr_targets_us_allies_uoo13234021.pdf |
|
Details | Url | 1 | https://www.ncsc.gov.uk/files/advisory |
|
Details | Url | 1 | https://www.gov.uk/government/news/russia-uk-and-us-expose-global-campaigns-of-malign-activity-by-russian-intelligence-services |
|
Details | Url | 5 | https://www.ncsc.gov.uk/news/advisory-apt29-targets-covid-19-vaccine-development |
|
Details | Url | 2 | https://www.notion.so |
|
Details | Url | 3 | https://go.recordedfuture.com/hubfs/reports/cta-2023-0127.pdf |
|
Details | Url | 1 | https://microsoft.com/en-us/security/blog/2021/05/28/breaking-down-nobeliums-latest-early-stage-toolset |
|
Details | Url | 1 | https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction |