NetMedved: summer campaign against Russian organizations

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
NetMedved: Summer Campaign Against Russian Organizations 🐻👍
The PT ESC cyber intelligence group has recorded a new wave of activity by the NetMedved hacking group targeting Russian organizations. The social engineering scheme is the same as before: ZIP archives with decoy documents disguised as business correspondence and the NetSupportRAT final payload.
Compared to the previous campaign, the arsenal now includes:
• A dedicated redirect domain: allows delivery servers to be changed without rebuilding already-distributed malicious files.
• AES-128-CBC encryption of the PowerShell stage.
• A ZIP/JScript variant that does not contact external infrastructure: everything needed is embedded in the body of the .js file.
Separately, we were able to confirm that the group has been using the JScript vector since at least 2024 — characteristic samples were found during a retrospective search.
🔗 A full breakdown of the infection chains, the group’s techniques and tactics, as well as indicators of compromise — in our blog on Habr.
#TI #APT #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



