Researchers and U.S. authorities reported multiple spearphishing campaigns linked with moderate confidence to APT29/Nobelium/Cozy Bear that targeted government agencies, NGOs, research institutions, embassies, and other high-value organizations. In one campaign, emails impersonating USAID used Constant Contact links to deliver malicious ISO files containing a decoy PDF, a weaponized .lnk shortcut, and a DLL loader that launched Cobalt Strike Beacon through rundll32.exe; CISA said the beacon used HTTP traffic disguised as requests for .woff2 files and embedded metadata in a _cfuid cookie while contacting infrastructure including theyardservice.com subdomains and worldhomeoutlet.com. Volexity also identified a second-stage malware family, FRESHFIRE, which retrieved encrypted payloads from Firebase and decrypted them with host-specific logic before deleting the remote content.
The activity fit a broader pattern seen in earlier and later operations attributed to the same cluster. FireEye documented a separate campaign in which attackers impersonated the U.S. Department of State, delivered ZIP archives with malicious shortcuts, used PowerShell to drop a decoy document, and installed Cobalt Strike Beacon communicating with pandorasong.com via a modified malleable C2 profile. Fortinet later described embassy-focused phishing that used HTML smuggling to build an ISO on the victim system, then relied on shortcut-triggered DLL execution to deploy another beacon, showing continued reuse of ISO-based delivery, decoy documents, and staged loaders across politically themed intrusion attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Volexity identified a phishing campaign on May 25, 2021 targeting organizations in the United States and Europe, including NGOs, research institutions, government agencies, and international agencies. The emails impersonated USAID and used Constant Contact links to deliver an ISO file that led to Cobalt Strike Beacon infection.
On November 14, 2018, FireEye detected targeted phishing against more than 20 clients across multiple sectors. The emails impersonated a U.S. Department of State Public Affairs official and delivered a ZIP with a weaponized LNK that installed a Cobalt Strike Beacon.
FireEye reported that the command-and-control domain pandorasong.com, used in a suspected APT29 phishing campaign, was registered as part of attacker infrastructure setup.
FortiGuard Labs reported a spearphishing campaign attributed to Nobelium/APT29 targeting embassy-associated Windows users with Omicron/COVID-19 themed lures. The attack used HTML smuggling to create an ISO file that mounted malicious shortcuts and loaded a DLL deploying Cobalt Strike Beacon via sinitude.com infrastructure.
CISA and the FBI released a malware analysis report on three malicious ISO files tied to the spearphishing campaign spoofing a U.S. government organization via Constant Contact. The report documented the malicious LNK, decoy PDF, custom Cobalt Strike Beacon DLL loader, and command-and-control infrastructure on theyardservice.com and worldhomeoutlet.com.
Volexity published technical analysis of the USAID-themed campaign, assessing with moderate confidence that APT29 was likely responsible based on overlaps in lures, delivery methods, infrastructure, and tooling. The report also identified and named a second-stage malware family, FRESHFIRE, which used Firebase-hosted encrypted payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourceus-cert.cisa.gov
Open sourcevolexity.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.