BlueBravo Uses Ambassador Lure to Deploy GraphicalNeutrino Malware
ID: d7b5a9d3-7449-4c68-8fcd-486386cd9ee3
STIX ID: report--d7b5a9d3-7449-4c68-8fcd-486386cd9ee3
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2023-01-30
Last Modified Date: 2023-01-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports that the threat group BlueBravo (linked to APT29/NOBELIUM) used an embassy-themed "Ambassador" lure and HTML smuggling to deliver a ZIP containing a malicious renamed 7-Zip executable and modified DLLs. The payload, GraphicalNeutrino, is a C++ loader that uses DLL search-order hijacking, anti-analysis techniques, and the Notion API as an innovative C2 channel to stage and retrieve encrypted shellcode; the report provides IoCs, technical analysis, Mitre ATT&CK mappings, a YARA rule, and recommended mitigations.
