logo

APT28 Targets Hospitality Sector, Presents Threat to Travelers « Threat Research Blog | FireEye Inc

ID: 4784b82a-4c88-41ea-9f2c-d7a1f5aca415

STIX ID: report--4784b82a-4c88-41ea-9f2c-d7a1f5aca415

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2017-08-11

Last Modified Date: 2017-08-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye attributes a campaign to APT28 that targeted hotels across Europe and the Middle East using a spear-phishing document (Hotel_Reservation_Form.doc) which drops GAMEFISH malware; the actor leveraged Responder for NetBIOS/NBT-NS poisoning to harvest credentials and used the EternalBlue SMB exploit and py2exe-compiled tools for lateral movement, with observed IOCs including MD5 hashes and the mvband.net C2 domain. The report warns travelers and hospitality operators about credential theft via public Wi‑Fi and the evolving tactics of state-aligned actors.