APT28__2020__APT28_Delivers_Zebrocy_Malware_Campaign_Using_NATO_Theme_as_Lure.pdf
ID: 0622a0c8-f533-47c3-831a-ea2ecd312878
STIX ID: report--0622a0c8-f533-47c3-831a-ea2ecd312878
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2020-09-24
Last Modified Date: 2020-09-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** QuoIntelligence detected an APT28 campaign (starting ~5 August 2020) using a NATO-themed JPEG/ZIP attachment that drops a Delphi Zebrocy executable which persists via scheduled tasks, harvests screenshots and posts encrypted data to an active C2 (194.32.78.245); the report includes file hashes, network IOC, MITRE ATT&CK mappings, victimology (government targets, at least one in Azerbaijan), and links the activity to known APT28 TTPs.
