BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware
ID: 809fa738-9da2-4829-97cf-abdab3b2354a
STIX ID: report--809fa738-9da2-4829-97cf-abdab3b2354a
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2023-07-26
Last Modified Date: 2023-07-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future Insikt Group reports on BlueBravo (overlapping with APT29/Midnight Blizzard) activity from H1 2023, describing spearphishing-driven campaigns that deliver loaders (GraphicalNeutrino, GraphicalProton, QuarterRig) staged in ISO/ZIP files, use HTML smuggling and compromised websites, and abuse legitimate cloud services (OneDrive, Notion, Dropbox) for command-and-control; the report includes detailed malware behavior, infrastructure IOCs, YARA rules, ATT&CK mappings, and defensive mitigations.
