APT29 attacks Embassies using CVE-2023-38831 - report
ID: 3d0f87a0-7667-4e8f-9556-5211393f7b72
STIX ID: report--3d0f87a0-7667-4e8f-9556-5211393f7b72
Threat Score
88/100
Uploaded: 2026-08-11
Published Date: 2023-11-15
Last Modified Date: 2023-11-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report details a cross-country APT29 campaign using CVE-2023-38831 in WinRAR to deliver a lure PDF from themed RAR archives ("DIPLOMATIC-CAR-FOR-SALE-BMW.rar"), execute PowerShell to retrieve a next-stage payload hosted via an ngrok subdomain, and target embassies and international organizations in Azerbaijan, Greece, Romania, and Italy; the document provides IoCs (filenames, hashes, URL/domain, email), attack timeline, and mitigation advice to update WinRAR to 6.23+.
