Itg05

Threat Actor updated 3 months ago (2024-08-14T09:20:12.569Z)
Download STIX
Preview STIX
ITG05, also known as Fancy Bear, Forest Blizzard, and APT28, among other aliases, is a sophisticated threat actor that has been involved in several cyber operations with malicious intent. The group has been leveraging the Israel-Hamas conflict to deliver Headlace malware, targeting non-governmental organizations (NGOs) through phishing lures. They have shown adaptability by delivering new infection methodologies and evolving their malware capabilities. In a recent change to their methods, ITG05 utilized the freely available hosting provider, firstcloudit[.]com to stage payloads for ongoing operations. Their elaborate scheme culminates in the execution of MASEPIE, OCEANMAP, and STEELHOOK, which are designed to exfiltrate files, run arbitrary commands, and steal browser data. The attackers impersonate government and NGO organizations across Europe, South Caucasus, Central Asia, North and South America, reaching victims via email. Their modus operandi involves deploying multiple lure documents disguised as authentic materials from entities in various countries including Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the United States. Despite this wide-reaching operation, IBM X-Force does not currently have insight into whether ITG05 has successfully compromised the impersonated organizations. ITG05 is expected to continue leveraging attacks against world governments and political apparatus to provide Russia with advanced insights into emerging policy decisions. For instance, after Argentina rejected an invitation to join the BRICS trade organization, it was suggested that ITG05 might seek to gain access to insights into Argentine government priorities. Given the group's adaptability and persistent evolution of their techniques, cybersecurity researchers warn of the continuous threat posed by ITG05.
Description last updated: 2024-08-14T08:42:05.685Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Forest Blizzard is a possible alias for Itg05. Forest Blizzard, also known as APT28, Fancy Bear, and Strontium, is a threat actor linked to the Russian General Staff Main Intelligence Directorate (GRU) and the 85th Main Special Service Center (GTsSS). The group has been involved in persistent espionage campaigns against European countries, which
2
APT28 is a possible alias for Itg05. APT28, also known as Fancy Bear and Unit 26165 of the Russian Main Intelligence Directorate, is a threat actor linked to Russia with a history of cyber-espionage activities. The group has been involved in several high-profile attacks, including the hacking of the Democratic National Committee (DNC)
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.