ZeroFox Intelligence Profile - APT28 Distributes New Malware Strains OCEANMAP, MASEPIE, and STEELHOOK
|by Alpha Team

ZeroFox Intelligence Profile - APT28 Distributes New Malware Strains OCEANMAP, MASEPIE, and STEELHOOK
Product Serial: P-2024-01-09a
TLP:CLEAR
In this Intelligence Profile, ZeroFox researchers provide an overview of APT28 and its background after it has been observed distributing new strains of malware.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Executive Summary
On December 28, 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory on a new phishing campaign by Russia state-affiliated Advanced Persistent Threat (APT) group APT28 (aka Fancy Bear, Sednit, Pawn Storm, and Sofacy Group). Detected between December 15 and December 25, the campaign utilizes previously undocumented malware strains—namely, OCEANMAP, MASEPIE, and STEELHOOK—to collect information from the networks of numerous Ukrainian government entities, as well as possibly several undisclosed Polish organizations. The extent of the sensitive information stolen in these attacks has not yet been publicly disclosed.
Tags: tlp:clear, eu/russia