Rewterz
Rewterz Threat Alert – APT10 MenuPass – Active IOCs
August 17, 2022
Rewterz
Rewterz Threat Alert – RedLine Stealer – Active IOCs
August 17, 2022

Rewterz Threat Alert – APT29 Cozy Bear – Active IOCs

Severity

High

Analysis Summary

APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.

Impact

  • Information Theft and Espionage
  • Exposure of Sensitive Data

Indicators of Compromise

MD5

  • da5915d2d579b45d757ac5b2d714ac73

SHA-256

  • 296fd7828080b03aba311459f090a5e11581aa43669d77fd9677188ec62fafa5

SHA-1

  • 4cfb17b4d1d43158abc6f18427897d4290bd7be3

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment