APT28 uses fake Windows Update instructions to target Ukraine
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-6742 | Authenticated SNMP Remote Code Execution in Cisco IOS and IOS XE Software CVE-2017-6742 is a memory-corruption flaw (CWE-119) in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE. It is triggered when an affected device processes crafted SNMP packets sent by an authenticated, remote attacker, meaning the device must have SNMP enabled and the attacker must hold valid SNMP credentials or community strings. Successful exploitation lets the attacker execute code on the router or switch, or force the device to reload, yielding either full control of the device or a denial of service on critical network infrastructure. Any organization running vulnerable Cisco IOS or IOS XE releases with SNMP enabled on routers, switches, or other network devices is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-19), confirming in-the-wild exploitation; EPSS estimates a 21.4% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept code is known. Do: Upgrade affected Cisco IOS and IOS XE devices to fixed releases per Cisco's advisory, prioritizing internet-facing routers and switches as the KEV listing makes patching mandatory for federal agencies and urgent for others. As interim mitigation, restrict SNMP access to trusted management hosts with ACLs, disable SNMP entirely where it is not required, and rotate SNMP community strings/credentials that could be used for authentication. Inventory devices for enabled SNMP services and vulnerable releases, focusing first on edge and internet-exposed infrastructure. | 8.8 | 21% | KEV |
| masson the order of hundreds of thousands of systems (well above 100k affected/exposed devices, given Cisco's installed base) |
Full article612 words · extracted from securityaffairs.com · click to collapse

CERT-UA warns of a spear-phishing campaign conducted by APT28 group targeting Ukrainian government bodies with fake ‘Windows Update’ guides.
Russia-linked APT28 group is targeting Ukrainian government bodies with fake ‘Windows Update’ guides, Computer Emergency Response Team of Ukraine (CERT-UA) warns.
The APT28 group (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, and STRONTIUM) has been active since at least 2007 and it has targeted governments, militaries, and security organizations worldwide. The group was involved also in the string of attacks that targeted 2016 Presidential election.
The group operates out of military unity 26165 of the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS).
Most of the APT28s’ campaigns leveraged spear-phishing and malware-based attacks.
CERT-UA observed the campaign in April 2023, the malicious e-mails with the subject “Windows Update” were crafted to appear as sent by system administrators of departments of multiple government bodies. The threat actors sent the messages from e-mail addresses created on the public service “@outlook.com.”
“During April 2023, the government computer emergency response team of Ukraine CERT-UA recorded cases of the distribution of e-mails with the subject “Windows Update” among government bodies of Ukraine, sent, apparently, on behalf of system administrators of departments. At the same time, e-mail addresses of senders created on the public service “@outlook.com” can be formed using the employee’s real surname and initials.” reads the alert published by CERT-UA. “The sample letter contains “instructions” in Ukrainian for “updates to protect against hacker attacks”, as well as graphical images of the process of launching a command line and executing a PowerShell command.”
The attackers used @outlook.com email addresses using real employee names that were previously obtained in a reconnaissance phase.
The content of the messages attempts to trick recipients into launching a command line and executing a PowerShell command.
Upon executing the command, it downloads a PowerShell script on the computer that simulates a Windows updating process while downloading another PowerShell script in the background.
This second-stage payload abuses the ‘tasklist’ and ‘systeminfo’ commands to gather system information and send them to a Mocky service API via an HTTP request.
“The mentioned command will download a PowerShell script that, simulating the process of updating the operating system, will download and execute the following PowerShell script designed to collect basic information about the computer using the “tasklist”, “systeminfo” commands, and send the received results using HTTP request to the Mocky service API.” continues the alert.
The CERT-UA recommends restricting the ability of users to launch PowerShell and monitor network connections to the Mocky service API.

CERT-UA also provided Indicators of Compromise for this campaign.
Recently, UK and US agencies are warned of the APT28 group exploiting vulnerabilities in Cisco networking equipment.
The Russia-linked APT group accesses unpatched Cisco routers to deploy malware exploiting the not patched CVE-2017-6742 vulnerability (CVSS score: 8.8), states a joint report published by the UK National Cyber Security Centre (NCSC), the US National Security Agency (NSA), US Cybersecurity and Infrastructure Security Agency (CISA) and US Federal Bureau of Investigation (FBI).
The joint advisory provides detailed info on tactics, techniques, and procedures (TTPs) associated with APT28’s attacks conducted in 2021 that exploited the flaw in Cisco routers.
Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:
- The Teacher – Most Educational Blog
- The Entertainer – Most Entertaining Blog
- The Tech Whizz – Best Technical Blog
- Best Social Media Account to Follow (@securityaffairs)
Please nominate Security Affairs as your favorite blog.
Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, APT28)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/145500/apt/spear-phishing-campaign-apt28.html