Frozenbarents, also known as Sandworm or Voodoo Bear, is a threat actor linked to Russia's GRU military intelligence agency. Noted for its versatility, the group has executed a variety of cyber-attacks against Ukraine and NATO countries, with a particular emphasis on critical infrastructure, utilities, public services, and the media. The group's activities have been tracked by Google's Threat Analysis Group (TAG), which observed Frozenbarents impersonating a Ukrainian drone training school in April.
The threat actor used an email lure themed as an invitation to join the drone school to deliver the Rhadamanthys infostealer, a type of malware designed to steal information from infected systems. This email contained a link to an anonymous file-sharing service, fex[.]net, which delivered a benign decoy PDF document with a drone operator training curriculum and a malicious ZIP file exploiting CVE-2023-38831. The use of commercially available infostealers, typically employed by cybercrime actors, is unusual for Frozenbarents.
Frozenbarents' campaigns have targeted various sectors, including the energy sector and ongoing hack-and-leak operations. One phishing campaign attributed to the group involved a decoy message about training drone operators that led to a packed version of the Rhadamanthys information-stealing malware. The TAG team has reported that the group's activities are part of a broader pattern of Russian and Belarusian cyber activities focused on targeting Ukraine, with other threat actors such as Frozenlake (aka APT28) and Pushcha (a Belarusian threat actor) also involved.
Description last updated: 2024-05-04T20:27:57.635Z