logo

BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware

ID: 809fa738-9da2-4829-97cf-abdab3b2354a

STIX ID: report--809fa738-9da2-4829-97cf-abdab3b2354a

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2023-07-26

Last Modified Date: 2023-07-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future Insikt Group reports on BlueBravo (overlapping with APT29/Midnight Blizzard) activity from H1 2023, describing spearphishing-driven campaigns that deliver loaders (GraphicalNeutrino, GraphicalProton, QuarterRig) staged in ISO/ZIP files, use HTML smuggling and compromised websites, and abuse legitimate cloud services (OneDrive, Notion, Dropbox) for command-and-control; the report includes detailed malware behavior, infrastructure IOCs, YARA rules, ATT&CK mappings, and defensive mitigations.