logo

Ghostwriter__2022__Proofpoint_Asylum-Ambuscade-Ukrainian-Military-Emails-Target-European_03-01-2022.pdf

ID: 3f8c001b-e10d-46f0-9a2e-de3cb8d77082

STIX ID: report--3f8c001b-e10d-46f0-9a2e-de3cb8d77082

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2022-03-04

Last Modified Date: 2022-03-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint researchers detail the “Asylum Ambuscade” phishing campaign that abused compromised Ukrainian personal emails to target European government personnel involved with refugee logistics; attackers delivered macro-enabled XLS files that silently invoked Windows Installer to fetch an MSI which installed Lua dependencies and a SunSeed Lua downloader establishing LNK persistence and HTTP C2 beacons (notable IOCs include 84.32.188.96, qwerty_setup.msi, print.lua and multiple file hashes). The report documents the macro and MSI behavior, SunSeed’s C2 pattern, victimology, YARA rules and IOCs, and assesses possible but unconfirmed links to TA445/UNC1151 and a similar July 2021 campaign.