APT28 Targets Hospitality Sector, Presents Threat to Travelers « Threat Research Blog | FireEye Inc
ID: 4784b82a-4c88-41ea-9f2c-d7a1f5aca415
STIX ID: report--4784b82a-4c88-41ea-9f2c-d7a1f5aca415
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2017-08-11
Last Modified Date: 2017-08-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye attributes a campaign to APT28 that targeted hotels across Europe and the Middle East using a spear-phishing document (Hotel_Reservation_Form.doc) which drops GAMEFISH malware; the actor leveraged Responder for NetBIOS/NBT-NS poisoning to harvest credentials and used the EternalBlue SMB exploit and py2exe-compiled tools for lateral movement, with observed IOCs including MD5 hashes and the mvband.net C2 domain. The report warns travelers and hospitality operators about credential theft via public Wi‑Fi and the evolving tactics of state-aligned actors.
