PULSE NAME
APT28 Targets Hospitality Sector, Presents Threat to Travelers
WHITE Sofacy AlienVault 2017-08-11 Modified: 2017-08-11
4
IOCs
LOW VOLUME
FireEye has moderate confidence that a campaign targeting the hospitality sector is attributed to Russian actor APT28. We believe this activity, which dates back to at least July 2017, was intended to target travelers to hotels throughout Europe and the Middle East. The actor has used several notable techniques in these incidents such as sniffing passwords from Wi-Fi traffic, poisoning the NetBIOS Name Service, and spreading laterally via the EternalBlue exploit.
Indicators of Compromise (2 / 4 total)
All domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1421419d1be31f1f9ea60e8ed87277db 2017-08-11
FileHash-MD5 9b10685b774a783eabfecdb6119a8aa3 2017-08-11