“Cyber Conflict” Decoy Document Used In Real Cyber Conflict
ID: b5f72fee-1994-4f56-8989-95bd3d001e4b
STIX ID: report--b5f72fee-1994-4f56-8989-95bd3d001e4b
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2018-02-04
Last Modified Date: 2018-02-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos describes a targeted campaign by Group 74 (APT28) using a malicious Word flyer with an embedded VBA macro that decodes and writes a PE (netwf.dat) to disk, executes it via rundll32 (KlpSvc export), and installs Seduploader reconnaissance malware. The report details the macro behavior, dropper and payload analysis (including XOR key and mutex changes), persistence mechanisms (UserInitMprLogonScript and COM object hijack of MMDeviceEnumerator), C2 domain (myinvestgroup.com), sample hashes, and detection/mitigation recommendations along with IOC listings.
