logo

BlueBravo Uses Ambassador Lure to Deploy GraphicalNeutrino Malware

ID: d7b5a9d3-7449-4c68-8fcd-486386cd9ee3

STIX ID: report--d7b5a9d3-7449-4c68-8fcd-486386cd9ee3

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2023-01-30

Last Modified Date: 2023-01-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports that the threat group BlueBravo (linked to APT29/NOBELIUM) used an embassy-themed "Ambassador" lure and HTML smuggling to deliver a ZIP containing a malicious renamed 7-Zip executable and modified DLLs. The payload, GraphicalNeutrino, is a C++ loader that uses DLL search-order hijacking, anti-analysis techniques, and the Notion API as an innovative C2 channel to stage and retrieve encrypted shellcode; the report provides IoCs, technical analysis, Mitre ATT&CK mappings, a YARA rule, and recommended mitigations.