APT28__2023__ITG05_operations_leverage_Israel-Hamas_conflict_lures_to_deliver_Headlace_malware_12-08-2023.pdf
ID: 8b08830e-ba1f-4222-95e5-5ddb0ed80346
STIX ID: report--8b08830e-ba1f-4222-95e5-5ddb0ed80346
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2023-12-19
Last Modified Date: 2023-12-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
IBM X-Force details a targeted ITG05 (likely Russian state-sponsored) campaign that weaponized authentic policy and diplomatic documents related to the Israel–Hamas conflict to deliver the Headlace multi-component backdoor. The multi-stage infection chains leverage CVE-2023-38831 WinRAR exploitation, DLL hijacking, geofenced JavaScript droppers hosted on abused commercial services, and headless MS Edge to fetch follow-on payloads; the report includes extensive IoCs (URLs, file hashes), observed TTPs, and defensive recommendations.
