My colleagues identified staging infrastructure from (activity overlapping with and NOBELIUM) hosting malware within a malicious ZIP file. Besides using a compromised website as part of the lure operation, the use of for C2 is particularly interesting: recordedfuture.com/bluebravo-u

#bluebravo #apt29 #graphicalneutrino #notion

Last updated 3 years ago