logo

APT29 attacks Embassies using CVE-2023-38831 - report

ID: 3d0f87a0-7667-4e8f-9556-5211393f7b72

STIX ID: report--3d0f87a0-7667-4e8f-9556-5211393f7b72

Threat Score

88/100

Uploaded: 2026-08-11

Published Date: 2023-11-15

Last Modified Date: 2023-11-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report details a cross-country APT29 campaign using CVE-2023-38831 in WinRAR to deliver a lure PDF from themed RAR archives ("DIPLOMATIC-CAR-FOR-SALE-BMW.rar"), execute PowerShell to retrieve a next-stage payload hosted via an ngrok subdomain, and target embassies and international organizations in Azerbaijan, Greece, Romania, and Italy; the document provides IoCs (filenames, hashes, URL/domain, email), attack timeline, and mitigation advice to update WinRAR to 6.23+.