PULSE NAME
Fancy Bear Phishing
WHITE Sofacy AlienVault 2019-07-16 Modified: 2019-07-18
20
IOCs
MEDIUM VOLUME
One domain targets a Singapore-based investment firm, and another references the Berlin anti-corruption organization Transparency International, which Russia has targeted before. Others are generic or ambiguous in their targeting. But one seized domain, soros-my-sharepoint[.]com, jumps out as a clear reference to Soros, a past GRU target from Russia’s 2016 election interference. An additional four phishing domains registered in the same time frame appear to target Soros Open Society Foundations, said Kyle Ehmke, an intelligence researcher at the Arlington, Virginia-based cybersecurity firm ThreatConnect. Those domains haven’t been seized and ThreatConnect hasn’t found enough evidence to definitively link them to the Russian hackers, said Ehmke.
Indicators of Compromise (20)
All domain hostname URL email
TYPEINDICATORDESCRIPTIONCREATED
domain osfam.events 2019-07-16
domain office365-osi.am 2019-07-16
domain office365-osf.am 2019-07-16
domain osfam.team 2019-07-16
domain soros-my-sharepoint.com 2019-07-16
domain irf.services 2019-07-16
domain sharepoint-democracyendowment.eu 2019-07-16
domain office365-democracyendowment.eu 2019-07-16
hostname office365.irf.services 2019-07-16
URL http://mircosoft.pictures/ 2019-07-18
URL http://okexe.cc/ 2019-07-18
email sickresign@protonmail.com 2019-07-18
email assumedough@protonmail.com 2019-07-18
email advertisingbase@protonmail.com 2019-07-18
domain mircosoft.pictures 2019-07-18
domain okexe.co 2019-07-18
domain okexe.mn 2019-07-18
domain okexe.cc 2019-07-18
domain questwitch.com 2019-07-18
domain okexe.uk 2019-07-18