logo

APT28__2023__ITG05_operations_leverage_Israel-Hamas_conflict_lures_to_deliver_Headlace_malware_12-08-2023.pdf

ID: 8b08830e-ba1f-4222-95e5-5ddb0ed80346

STIX ID: report--8b08830e-ba1f-4222-95e5-5ddb0ed80346

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2023-12-19

Last Modified Date: 2023-12-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
IBM X-Force details a targeted ITG05 (likely Russian state-sponsored) campaign that weaponized authentic policy and diplomatic documents related to the Israel–Hamas conflict to deliver the Headlace multi-component backdoor. The multi-stage infection chains leverage CVE-2023-38831 WinRAR exploitation, DLL hijacking, geofenced JavaScript droppers hosted on abused commercial services, and headless MS Edge to fetch follow-on payloads; the report includes extensive IoCs (URLs, file hashes), observed TTPs, and defensive recommendations.