Ghostwriter__2022__Proofpoint_Asylum-Ambuscade-Ukrainian-Military-Emails-Target-European_03-01-2022.pdf
ID: 3f8c001b-e10d-46f0-9a2e-de3cb8d77082
STIX ID: report--3f8c001b-e10d-46f0-9a2e-de3cb8d77082
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2022-03-04
Last Modified Date: 2022-03-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint researchers detail the “Asylum Ambuscade” phishing campaign that abused compromised Ukrainian personal emails to target European government personnel involved with refugee logistics; attackers delivered macro-enabled XLS files that silently invoked Windows Installer to fetch an MSI which installed Lua dependencies and a SunSeed Lua downloader establishing LNK persistence and HTTP C2 beacons (notable IOCs include 84.32.188.96, qwerty_setup.msi, print.lua and multiple file hashes). The report documents the macro and MSI behavior, SunSeed’s C2 pattern, victimology, YARA rules and IOCs, and assesses possible but unconfirmed links to TA445/UNC1151 and a similar July 2021 campaign.
