← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
APT28 Targets Hospitality Sector, Presents Threat to Travelers
FireEye has moderate confidence that a campaign targeting the hospitality sector is attributed to Russian actor APT28. We believe this activity, which dates back to at least July 2017, was intended to target travelers to hotels throughout Europe and the Middle East. The actor has used several notable techniques in these incidents such as sniffing passwords from Wi-Fi traffic, poisoning the NetBIOS Name Service, and spreading laterally via the EternalBlue exploit.
Indicators of Compromise (4)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | mvband.net | — | 2017-08-11 | |
| domain | mvtband.net | — | 2017-08-11 | |
| FileHash-MD5 | 1421419d1be31f1f9ea60e8ed87277db | — | 2017-08-11 | |
| FileHash-MD5 | 9b10685b774a783eabfecdb6119a8aa3 | — | 2017-08-11 |