logo

Pawn Storm Uses Brute Force and Stealth Against High-Value Targets | Trend Micro (US)

ID: 7d0ea37f-9ec4-4a1a-ab9f-797a23bd02d9

STIX ID: report--7d0ea37f-9ec4-4a1a-ab9f-797a23bd02d9

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2024-06-27

Last Modified Date: 2024-06-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Pawn Storm (also tracked as APT28/Forest Blizzard) continues aggressive and persistent targeting of high-value government, defense, energy, and infrastructure organizations worldwide by combining large-scale brute-force credential probing with stealthier post-compromise techniques. The report details use of anonymization layers (commercial VPNs, Tor, compromised EdgeOS routers), spear-phishing deliveries including CVE-2023-23397 (Outlook) Net-NTLMv2 hash relay attacks and a WinRAR exploit, example scripts and captures that exfiltrate Net-NTLMv2 blobs, a standalone information stealer that exfiltrates files via free file hosts and TinyURL aliases, and provides IOCs and detection guidance for defenders.