[ << ALL_FEED ]

Cloud services from the operator "MeHaFon"

More in General

📲 Cloud services from the “MeHaFon” operator

News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government organizations in Russia and CIS countries. We covered this group in our research APT Cloud Atlas: Unbroken Threat and in a post.

📝 As the initial vector in their attacks, the threat actors traditionally use phishing emails with a malicious attachment “О представлении информации.doc” (VirusTotal 0/62). The emails are sent from @internet.ru addresses. This email domain can be obtained by registering with the mail.ru service.

It is noteworthy that the attackers are staying true to themselves and have been using cloud services since 2014. At the same time, they continue to experiment, and new popular platforms are added to their arsenal time and again. Therefore, first and foremost, we strongly recommend checking all sessions over the “Yandex Disk WebDAV” protocol (webdav.yandex.ru) and requests via the Google Sheets API (oauth2.googleapis.com, sheets.googleapis.com).

IoCs:


mehafon.com
technoguides.org

9943fee873c0642216d1578fc4373648b670b5bc47a8bf37366063041518f8b2

Happy hunting and stay tuned!

#hunt #detect #ioc #apt #news
@ptescalator

More from global_author

More from global_author

More in General