Primitive Bear spearphishes for Ukrainian entities. [Research Saturday]

Published: June 19, 2021, 7 a.m.

b'Guests Gage Mele and Yury Polozov join Dave to talk about Anomali\'s research "Primitive Bear (Gamaredon) Targets Ukraine with Timely Themes." Anomali Threat Research identified malicious samples that align with the Russia-sponsored cyberespionage group Primitive Bear\\u2019s (Gamaredon, Winterflounder) tactics, techniques, and procedures (TTPs). Primitive Bear, known primarily to focus on Ukraine, has been very active in 2021. However, the themes of the samples Anomali found, as well as those shared by the security community, could also be used to target multiple former Union of Soviet Socialist Republic (USSR) countries. Anomali Threat Research found malicious .docx files being distributed by Primitive Bear, likely through spearphishing, that attempted to download remote template .dot files through template injection.\\nThe research can be found here:\\nPrimitive Bear (Gamaredon) Targets Ukraine with Timely Themes'