logo

BfV Cyber-Brief Nr. 01/2022

ID: 68b66b3e-b7c8-45d8-bddf-13a24fa2e436

STIX ID: report--68b66b3e-b7c8-45d8-bddf-13a24fa2e436

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2022-01-25

Last Modified Date: 2022-01-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BfV warns of an ongoing APT27 cyberespionage campaign (since March 2021) targeting German companies by exploiting Microsoft Exchange and Zoho ADSelfService Plus vulnerabilities to deploy the HYPERBRO RAT; the report provides detailed technical analysis of HYPERBRO's components, installation/execution flow, persistence techniques, C2 behavior, indicators of compromise (IP addresses, file paths, mutexes, named pipe, registry keys) and YARA detection rules, and recommends scanning logs and networks (including historical logs since Feb 2021) using the supplied IOCs and rules.