PULSE NAME
Cloaked Ursa (APT29) Hackers Use Trusted Online Storage Services
WHITE APT29 AlienVault 2022-07-20 Modified: 2022-08-19
22
IOCs
MEDIUM VOLUME
Organizations around the world rely on the use of trusted, reliable online storage services – such as DropBox and Google Drive – to conduct day-to-day operations. However, our latest research shows that threat actors are finding ways to take advantage of that trust to make their attacks extremely difficult to detect and prevent. The latest campaigns conducted by an advanced persistent threat (APT) that we track as Cloaked Ursa (also known as APT29, Nobelium or Cozy Bear) demonstrate sophistication and the ability to rapidly integrate popular cloud storage services to avoid detection.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
EnvyScout Cobalt Strike
Indicators of Compromise (2 / 22 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 c825e55012a3d236e4eca7b005b44fff MD5 of 761ed73512cb4392b98c84a34d3439240a73e389f09c2b4a8f0cce6a212f529c 2022-07-20
FileHash-MD5 f51a8644e97007417e3ef3a61991e293 MD5 of ce9802b22a37ae26c02b1f2c3225955a7667495fce5b106113434ab5a87ae28a 2022-07-20