The campaign targeted diplomats with a car-for-sale phishing lure delivering the HeadLace backdoor, attributed to APT28, known by various aliases, reusing tactics from APT29.
APT28 leverages webhook[.]site and decoy images like Audi Q7 Quattro SUV to deliver malicious files, including a disguised Windows calculator executable to sideload the HeadLace backdoor.
Collection
[
|
...
]