BfV Cyber-Brief Nr. 01/2022
ID: 68b66b3e-b7c8-45d8-bddf-13a24fa2e436
STIX ID: report--68b66b3e-b7c8-45d8-bddf-13a24fa2e436
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2022-01-25
Last Modified Date: 2022-01-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BfV warns of an ongoing APT27 cyberespionage campaign (since March 2021) targeting German companies by exploiting Microsoft Exchange and Zoho ADSelfService Plus vulnerabilities to deploy the HYPERBRO RAT; the report provides detailed technical analysis of HYPERBRO's components, installation/execution flow, persistence techniques, C2 behavior, indicators of compromise (IP addresses, file paths, mutexes, named pipe, registry keys) and YARA detection rules, and recommends scanning logs and networks (including historical logs since Feb 2021) using the supplied IOCs and rules.
