PULSE NAME
Operation RussianDoll
WHITE Sofacy AlienVault 2015-04-20 Modified: 2017-08-24
9
IOCs
LOW VOLUME
FireEye Labs recently detected a limited APT campaign exploiting zero-day vulnerabilities in Adobe Flash and a brand-new one in Microsoft Windows. Using the Dynamic Threat Intelligence Cloud (DTI), FireEye researchers detected a pattern of attacks beginning on April 13th, 2015. Adobe independently patched the vulnerability (CVE-2015-3043) in APSB15-06. Through correlation of technical indicators and command and control infrastructure, FireEye assess that APT28 is probably responsible for this activity.
Indicators of Compromise (9)
All domain CVE
TYPEINDICATORDESCRIPTIONCREATED
domain ssl-icloud.com 2017-08-24
CVE CVE-2015-3043 2017-08-24
CVE CVE-2015-1701 2017-08-24
CVE CVE-2014-0515 2017-08-24
domain updatecenter.name 2017-08-24
domain securitypractic.com 2017-08-24
domain pass-google.com 2017-08-24
domain drivers-update.info 2017-08-24
domain nato-press.com 2017-08-24