216.73.216.6

Sophisticated Malware Campaign Targets Czech Officials Using NATO-Themed Decoys

· Published 28/08/2024 09:27 · Modified 28/08/2024 09:35

Export JSON

Essential information

Published
28/08/2024 09:27
Modified
28/08/2024 09:35
Tags
2024-08-28 czech republic decoy evasion freeze havoc injection nato persistence rust
Related entities
13 observables, 10 techniques (mitre), 2 malware

Description

Seqrite Labs APT-Team discovered a sophisticated malware campaign targeting government and military officials in the . The campaign leveraged -themed documents to lure victims and employed a multistage attack chain involving a malicious batch script, a -based loader, and the post-exploitation framework. The campaign utilized advanced techniques like ETW patching, process , and encrypted payloads to evade detection and establish on compromised systems. The threat actor behind the operation appears to have Russian origins and used open-source offensive tools extensively.

External references