logo

APT28__2020__APT28_Delivers_Zebrocy_Malware_Campaign_Using_NATO_Theme_as_Lure.pdf

ID: 0622a0c8-f533-47c3-831a-ea2ecd312878

STIX ID: report--0622a0c8-f533-47c3-831a-ea2ecd312878

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2020-09-24

Last Modified Date: 2020-09-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** QuoIntelligence detected an APT28 campaign (starting ~5 August 2020) using a NATO-themed JPEG/ZIP attachment that drops a Delphi Zebrocy executable which persists via scheduled tasks, harvests screenshots and posts encrypted data to an active C2 (194.32.78.245); the report includes file hashes, network IOC, MITRE ATT&CK mappings, victimology (government targets, at least one in Azerbaijan), and links the activity to known APT28 TTPs.