logo

“Cyber Conflict” Decoy Document Used In Real Cyber Conflict

ID: b5f72fee-1994-4f56-8989-95bd3d001e4b

STIX ID: report--b5f72fee-1994-4f56-8989-95bd3d001e4b

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2018-02-04

Last Modified Date: 2018-02-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos describes a targeted campaign by Group 74 (APT28) using a malicious Word flyer with an embedded VBA macro that decodes and writes a PE (netwf.dat) to disk, executes it via rundll32 (KlpSvc export), and installs Seduploader reconnaissance malware. The report details the macro behavior, dropper and payload analysis (including XOR key and mutex changes), persistence mechanisms (UserInitMprLogonScript and COM object hijack of MMDeviceEnumerator), C2 domain (myinvestgroup.com), sample hashes, and detection/mitigation recommendations along with IOC listings.