[ << ALL_FEED ]

Who even are these PhaseShifters of yours?

More in General

😲 Who the heck are these PhaseShifters of yours?

In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack chain.

✍️ PhaseShifters (Sticky Werewolf, UAC-0050 ❓) is a hacker group engaged in espionage, whose attacks target various industries in Eastern European countries, including government agencies, the economic sector, and industry.

In their attacks, the group uses phishing: attackers send emails supposedly from officials requesting the recipient to review a document and sign it. The document is attached inside a password-protected archive. As malware, the attackers use Rhadamanthys, DarkTrack RAT, Meta Stealer, and others.

🔍 We have observed high activity from the group since spring 2023 and noticed one strange detail back then. The fact is that PhaseShifters group attacks are identical in techniques to the attacks of another group — UAC-0050. Moreover, the attacks occur with a short time gap, meaning the groups attack in the same way with a difference of several weeks to a month.

At this point, we lean toward the conclusion that UAC-0050 and PhaseShifters are the same group, but this can only be confirmed after longer-term observation.

⚠️ And it happened again…

This summer, both groups began using identical patterns in their attacks. It even got to the point where the groups’ malware was hosted in the same BitBucket repository. This prompted us to delve deeper into the matter.

📰 What attack was discovered, what similarities we observed, who was targeted, and what TA558 and Brazilian obfuscators and crypters have to do with it — you can find all this in our article.

#TI #Hunt #Malware #APT
@ptescalator

More from ti_author

More from ti_author

More in General