Tuesday, March 4, 2025
HomeHacksFancy Bear Hackers Back to Form & Launched Cyber Attack Again on...

Fancy Bear Hackers Back to Form & Launched Cyber Attack Again on various Government’s Computer Networks

Published on

SIEM as a Service

Follow Us on Google News

A new cyber attack launched against various Government’s Computer Networks by Sofacy hacking group which including a gang of cyber criminals (AKA APT28, Fancy Bear, STRONTIUM, Sednit, Tsar Team, Pawn Storm).

These group of hackers is one of the leading organized cybercrime group in the world and they are performing various attacks against the organization, government sectors as well as individuals.

Researchers identified initial attack targeting on two foreign affairs government institutions and it mainly belongs to Europe and the other in North America.

The sofacy hacking group using various pattern of attacks such as reuse of WHOIS artifacts, IP reuse, or even domain name themes also they registering new domains then placing a default landing page.

How Does this Cyber Attack has been Performed – Fancy Bear

This Attack initially distributed via phishing attack by sending specifically crafted email using the subject line of Upcoming Defense events February 2018 and the sender address claims that they associated with the defense and government sector.

Later deep header analysis revealed that concern received email has been spoofed and it did not come from the original source.

Also, Email contains malicious macro script enabled Excel XLS document but even it was a standard macro document, users need to enable the macro to view the hidden texts.

In this case, the white font color is applied to the text, so must enable the macro to view the original content.

Once the Macro will be enabled, content is presented via the following code:

ActiveSheet.Range(“a1:c54”).Font.Color = vbBlack

The code above changes the font color to black within the specified cell range and presents the content to the user.

Initially, it seems to be a legitimate content closer examination of the document later revealed several abnormal artifacts.

According to Paloaltonetworks malicious document, macro gets the contents of cells in column 170 in rows 2227 to 2248 to obtain the base64 encoded payload.

The macro sleeps for two seconds and then executes the newly dropped executable and the dropper executable is ultimately responsible for execution and running the payload.

The Trojan will use the same hashing algorithm for API resolution to find browser processes running on the system with the intention of injecting code into the browser to communicate with its C2 server.

In this case, Sofacy may have used an open-source tool called Luckystrike to generate the delivery document and/or the macro used in this attack.

Luckystrike is a Microsoft PowerShell-based tool that generates malicious delivery documents by allowing a user to add a macro to an Excel or Word document

The Sofacy group should no longer be an unfamiliar threat at this stage. They have been well documented and well researched with much of their attack methodologies exposed. They continue to be persistent in their attack campaigns and continue to use similar tooling as in the past. paloaltonetworks said.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Salt Typhoon Hacked Nine U.S. Telecoms, Tactics and Techniques Revealed

Salt Typhoon, a state-sponsored Advanced Persistent Threat (APT) group linked to the People's Republic...

APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub

The malicious Southeast Asian APT group known as OceanLotus (APT32) has been implicated in...

Casio Hacked – Servers Compromised by a Ransomware Attack

Casio Computer Co., Ltd. has confirmed a significant cybersecurity breach after its servers were...