Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It’s worth noting that the string encryption algorithms appear to line up with those seen within the Cloaked Ursa SNOWYAMBER and QUARTERRIG malware reports by the Military Counterintelligence Service and CERT.PL.
It’s worth noting that the string encryption algorithms appear to line up with those seen within the Cloaked Ursa SNOWYAMBER and QUARTERRIG malware reports by the Military Counterintelligence Service and CERT.PL.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Their initial access attempts over the past two years have predominantly used phishing lures with a theme of diplomatic operations... Cloaked Ursa emailed their illegitimate version of this flyer to multiple diplomatic missions throughout Kyiv. These illegitimate flyers use benign Microsoft Word documents of the same name.
For communication, the payload uses both the Microsoft Graph and Dropbox API... If communication fails via the Graph API several times, communication via Dropbox is attempted.
SNOWYAMBER – a tool first used in October 2022, abusing the Notion service to communicate and download further malicious files.
If the infected workstation passed manual verification, the aforementioned downloaders were used to deliver and start-up the commercial tools COBALT STRIKE or BRUTE RATEL.
Previously, Cloaked Ursa-linked payloads that communicate with Dropbox had wrapped communications in a packet that resembled an MP3 file... In this sample, it appears that they have opted to use BMP files. The threat actor-owned C2 will upload commands to Dropbox that are wrapped in the BMP format.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Cloaked Ursa-linked malware family referenced due to shared string-encryption and obfuscation techniques with the analyzed payloads.
A downloader first used in October 2022 that abuses Notion for communications and retrieval of additional malicious files. It also sends host and user details for victim triage before delivering follow-on tooling.
Downloader installed by EnvyScout to retrieve additional payloads in APT29 intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.