zerofox logo
Advisories

ZeroFox Intelligence Profile - APT28 Distributes New Malware Strains OCEANMAP, MASEPIE, and STEELHOOK

|by Alpha Team

banner image

ZeroFox Intelligence Profile - APT28 Distributes New Malware Strains OCEANMAP, MASEPIE, and STEELHOOK

Product Serial: P-2024-01-09a

TLP:CLEAR

In this Intelligence Profile, ZeroFox researchers provide an overview of APT28 and its background after it has been observed distributing new strains of malware.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here.

Executive Summary

On December 28, 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory on a new phishing campaign by Russia state-affiliated Advanced Persistent Threat (APT) group APT28 (aka Fancy Bear, Sednit, Pawn Storm, and Sofacy Group). Detected between December 15 and December 25, the campaign utilizes previously undocumented malware strains—namely, OCEANMAP, MASEPIE, and STEELHOOK—to collect information from the networks of numerous Ukrainian government entities, as well as possibly several undisclosed Polish organizations. The extent of the sensitive information stolen in these attacks has not yet been publicly disclosed.

Tags: tlp:clear,  eu/russia