{"id":563,"date":"2018-12-05T19:02:32","date_gmt":"2018-12-05T17:02:32","guid":{"rendered":"https:\/\/fortgale.com\/news\/?p=563"},"modified":"2026-06-08T22:52:22","modified_gmt":"2026-06-08T22:52:22","slug":"apt28-nato-event-targeting","status":"publish","type":"post","link":"https:\/\/fortgale.com\/blog\/emerging-threats\/apt28-nato-event-targeting\/","title":{"rendered":"APT28 leverages the NATO event"},"content":{"rendered":"<p style=\"text-align: justify\">Among the volume of cyberattacks recorded daily, there exist some of a more sophisticated nature: <strong>Advanced Persistent Threats<\/strong> (<strong>APT<\/strong>). This type of threat, often <strong><em>state-sponsored<\/em><\/strong>, appears in some cases attributable to a scenario of <strong>Cyber Warfare<\/strong>.<\/p>\n<p style=\"text-align: justify\">The objectives of this type of attack are typically <strong>intellectual property<\/strong>, <strong>personal information<\/strong>, or <strong>banking transactions<\/strong>.<\/p>\n<p style=\"text-align: justify\">To identify and counter these threats, a team of analysts equipped with appropriate defensive competencies and tools is required.<\/p>\n<p style=\"text-align: justify\">We present below the description of an attack characterized by the use of apparently credible documents as a compromise vector.<\/p>\n<h1>Attack Reconstruction<\/h1>\n<p style=\"text-align: justify\"><strong>Based on the evidence collected, the attack is attributable to the APT28 group (also known as Fancy Bear or Sofacy), likely of Russian nationality, which has employed the same modus operandi for several years.<\/strong><\/p>\n<p style=\"text-align: justify\">In the analysis of the attack, we identified the use of a Word document related to a NATO event scheduled for 11\u201313 December in the United States (<a href=\"https:\/\/events.sto.nato.int\/index.php\/upcoming-events\/event-list\/download.file\/791\">LINK TO NATO WORD DOCUMENT<\/a>). This document, used as a vector, was weaponized with malicious code overlapping with that previously used by the APT28 group.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/evento-300x243.png\" alt=\"\" width=\"780\" height=\"631\" class=\"wp-image-564 zoooom aligncenter\" loading=\"lazy\"><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The Word document used by the attackers differs from the original due to the insertion of a password-protected macro and the embedding of the <em>SedUploader<\/em> malware within it:<\/p>\n<figure id=\"attachment_567\" aria-describedby=\"caption-attachment-567\" style=\"width: 740px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/Word_Malware-1024x460.png\" alt=\"NATO Word Malware\" width=\"750\" height=\"337\" class=\"size-large wp-image-567 zoooom\" loading=\"lazy\"><figcaption id=\"caption-attachment-567\" class=\"wp-caption-text\">NATO Word Malware<\/figcaption><\/figure>\n<h1>The Malware<\/h1>\n<p style=\"text-align: justify\">Opening the document and executing the embedded code initiates the system compromise process and, consequently, creates the files &#8220;UpdaterUI.dll&#8221; and &#8220;Uplist.dat&#8221; and the registry key &#8220;UlMgr&#8221; to establish persistence. Our <a href=\"https:\/\/fortgale.com\/en\/cyber-threat-intelligence\/\">Cyber Threat Intelligence<\/a> analysis confirms the use of T1547.001 (Registry Run Keys \/ Startup Folder) for maintaining access across system reboots.<\/p>\n<table border=\"1\" style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/passwordMacro.png\" alt=\"\" width=\"1070\" height=\"340\" class=\"alignnone wp-image-580 zoooom\" loading=\"lazy\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 100%\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/binfile.png\" alt=\"\" width=\"1000\" height=\"345\" class=\"wp-image-575 zoooom alignnone\" loading=\"lazy\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table border=\"1\" style=\"border-collapse: collapse;width: 100%;height: 105px\">\n<tbody>\n<tr style=\"height: 105px\">\n<td style=\"width: 100%;height: 105px\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/macro-1024x140.png\" alt=\"\" width=\"750\" height=\"103\" class=\"aligncenter wp-image-576 size-large zoooom\" loading=\"lazy\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"1\" style=\"border-collapse: collapse;width: 100%;height: 148px\">\n<tbody>\n<tr style=\"height: 148px\">\n<td style=\"width: 50%;height: 148px\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/UpdaterUI.png\" alt=\"\" width=\"636\" height=\"264\" class=\"alignnone wp-image-584\" loading=\"lazy\"><\/td>\n<td style=\"width: 50%;height: 148px\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/Uplist-300x79.png\" alt=\"\" width=\"660\" height=\"174\" class=\"zoooom aligncenter wp-image-583\" loading=\"lazy\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"1\" style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/Persistence.png\" alt=\"\" width=\"927\" height=\"192\" class=\"alignnone wp-image-581 zoooom\" loading=\"lazy\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h1>Command and Control Server<\/h1>\n<p style=\"text-align: justify\">The malware proceeds to contact the <strong>command and control server<\/strong> registered at the domain &#8220;<em><strong>beatguitar.com<\/strong><\/em>&#8221; with IP address <em><a href=\"https:\/\/www.robtex.com\/ip-lookup\/185.99.133.72\">185.99.133.72<\/a><\/em><\/p>\n<div>\n<div class=\"family-reuse\">\n<div class=\"family-details\">\n<div class=\"family\" style=\"text-align: justify\">The malware employs an <strong>anti-analysis<\/strong> technique that checks for the presence of <strong>Wireshark software<\/strong> on the system. If detected, the malware instead contacts the domain &#8220;<em>google.com<\/em>&#8220;.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<h1 style=\"text-align: justify\">Attribution \u2013 APT28\/Fancy Bear\/Sofacy<\/h1>\n<p style=\"text-align: justify\">Attribution of an attack to the correct source is fundamental for identifying the objectives and possible motives of the action. This information is essential for conducting <strong>Incident Response<\/strong> activities within the infrastructure.<\/p>\n<p style=\"text-align: justify\">In this case, identification of the <strong>APT28<\/strong> group as the source of the attack is confirmed by the use of a YARA rule created specifically for this threat type and shared by analysts within the <a href=\"https:\/\/github.com\/Neo23x0\/signature-base\">Github<\/a> project:<\/p>\n<table border=\"1\" style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/fr_yara.png\" alt=\"\" width=\"527\" height=\"409\" class=\"zoooom wp-image-588 aligncenter\" loading=\"lazy\"><\/p>\n<p style=\"text-align: center\">YARA Rule<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 100%\">\n<p style=\"text-align: center\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/yara_rule-300x31.png\" alt=\"\" width=\"677\" height=\"70\" class=\"zoooom wp-image-589 aligncenter\" loading=\"lazy\">Rule Result<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Code Intelligence analysis also confirms the <strong>overlap of 97 code strings<\/strong> from the extracted malware with previous samples from the <strong>APT28<\/strong> (or <strong>Sofacy<\/strong>) group:<\/p>\n<table border=\"1\" style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2018\/12\/sofacy_related-1024x489.png\" alt=\"\" width=\"750\" height=\"358\" class=\"wp-image-592 size-large zoooom aligncenter\" loading=\"lazy\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<div>\n<div class=\"family-reuse\">\n<div class=\"family-details\">\n<div class=\"family\"><span style=\"font-size: 42px;text-align: justify\">References<\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p style=\"text-align: justify\">This analysis originates from evidence collected by a <strong><em>Threat Hunting<\/em><\/strong> team composed of <em><strong>@MD0ugh<\/strong><\/em>, <em><strong>@DrunkBinary<\/strong><\/em>, <em><strong>@r0ny_123<\/strong><\/em>, and <em><strong>@Manu_De_Lucia<\/strong><\/em>, which identified and analyzed the threat. Additional details are available at this <a href=\"https:\/\/www.emanueledelucia.net\/apt28-targeting-military-institutions\/\">link<\/a>. The convergence of macro-based delivery, SedUploader payload, and C2 infrastructure patterns demonstrates the persistent operational continuity of state-sponsored threat actors employing document-based infection chains against institutional targets.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT28 (Fancy Bear) timing operations around NATO events: spearphishing lures, fake credential portals, payload delivery patterns and attribution signals.<\/p>\n","protected":false},"author":1,"featured_media":567,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[32,33,141,1577,435,208,241,3225,3226,328,331],"class_list":["post-563","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-emerging-threats","tag-apt","tag-apt28","tag-fancy-bear","tag-fancy-bear-it","tag-fortgale-report","tag-macro","tag-nato","tag-nato-targeting","tag-russia-gru","tag-sofacy","tag-spearphishing"],"_links":{"self":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/comments?post=563"}],"version-history":[{"count":2,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/563\/revisions"}],"predecessor-version":[{"id":9878,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/563\/revisions\/9878"}],"wp:attachment":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/media?parent=563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/categories?post=563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/tags?post=563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}