Security News > 2022 > May > Researchers Find New Malware Attacks Targeting Russian Government Entities
![Researchers Find New Malware Attacks Targeting Russian Government Entities](/static/build/img/news/researchers-find-new-malware-attacks-targeting-russian-government-entities-medium.jpg)
An unknown advanced persistent threat group has been linked to a series of spear-phishing attacks targeting Russian government entities since the onset of the Russo-Ukrainian war in late February 2022.
The cybersecurity company attributed the attacks with low confidence to a Chinese hacking group, citing infrastructure overlaps between the RAT and Sakula Rat malware used by a threat actor known as Deep Panda.
The attack chains, while leveraging different lures over the course of two months, all employed the same malware barring small differences in the source code.
The development once again demonstrates threat actors' capabilities to adapt and adjust their attacks to world events, using the most relevant and up-to-date lures to maximize their chances of success.
"Interestingly, the threat actor created the Facebook page in June 2021, nine months before it was used in this campaign," the researchers said.
The third iteration of the attack that followed made use of another malicious executable file - this time "Build rosteh4.exe" - in an attempt to pass off the malware as though it's from Rostec.
News URL
https://thehackernews.com/2022/05/researchers-find-new-malware-attacks.html
Related news
- New IOCONTROL malware used in critical infrastructure attacks (source)
- FBI spots HiatusRAT malware attacks targeting web cameras, DVRs (source)
- Researchers reveal OT-specific malware in use and in development (source)
- Russian hackers use RDP proxies to steal data in MiTM attacks (source)
- Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack (source)
- Malware botnets exploit outdated D-Link routers in recent attacks (source)
- Ivanti zero-day attacks infected devices with custom malware (source)
- WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites (source)
- IPany VPN breached in supply-chain attack to push custom malware (source)
- MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks (source)