Ghostwriter__2022__Asylum_Ambuscade_State_Actor_Uses_Compromised_Private_Ukrainian_Military_Emails_to_Target_European_Governments_and_Refugee_Movement_Proofpoint_US.pdf
ID: 1dcbe550-476d-4c35-9411-8bb636fe4480
STIX ID: report--1dcbe550-476d-4c35-9411-8bb636fe4480
Threat Score
82/100
Uploaded: 2026-08-15
Published Date: 2022-04-27
Last Modified Date: 2022-04-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint describes a targeted phishing campaign that used compromised Ukrainian private military email accounts to send a macro-enabled XLS which silently invoked Windows Installer to download an MSI. The MSI deployed a Lua-based backdoor named SunSeed, installed Lua dependencies and an autorun LNK, and beacons to actor C2 servers (notably 84.32.188.96) appending the infected host's C: drive serial; the report provides technical analysis, IOCs (IPs, filenames, hashes) and assesses possible ties to TA445/UNC1151 while warning of continued targeting of European government entities handling refugee logistics.
