Fighting Ursa Luring Targets With Car For Sale
A Russian threat actor we track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024. Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content. Unit 42 has previously observed other threat groups using this tactic. For example, in 2023, a different Russian threat group, Cloaked Ursa, repurposed an advertisement for a BMW for sale to target diplomatic missions within Ukraine. This campaign is not directly connected to the Fighting Ursa campaign described here. However, the similarity in tactics points to known behaviors of Fighting Ursa. The Fighting Ursa group is known for repurposing successful tactics – even continuously exploiting known vulnerabilities for 20 months after their cover was already blown. The details of the March 2024 campaign, which we attribute to Fighting Ursa with a medium to high level of confidence, indicate the group targeted diplomats and relied on public and free services to host various stages of the attack. This article examines the infection chain from the attack. Palo Alto Networks customers are better protected from the threats discussed in this article through our Network Security solutions, such as Advanced WildFire and Advanced URL Filtering, as well as our Cortex line of products. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.
Unit42 Threat Brief - Fighting Ursa · 21 tasks · 2 inputs · 0 outputs
Details
| ID | Fighting Ursa Luring Targets With Car For Sale |
|---|---|
| From Version | 6.10.0 |
| Tasks | 21 |
README
A Russian threat actor we track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024. Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT).
Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content.
Unit 42 has previously observed other threat groups using this tactic. For example, in 2023, a different Russian threat group, Cloaked Ursa, repurposed an advertisement for a BMW for sale to target diplomatic missions within Ukraine. This campaign is not directly connected to the Fighting Ursa campaign described here. However, the similarity in tactics points to known behaviors of Fighting Ursa. The Fighting Ursa group is known for repurposing successful tactics – even continuously exploiting known vulnerabilities for 20 months after their cover was already blown.
The details of the March 2024 campaign, which we attribute to Fighting Ursa with a medium to high level of confidence, indicate the group targeted diplomats and relied on public and free services to host various stages of the attack. This article examines the infection chain from the attack.
Palo Alto Networks customers are better protected from the threats discussed in this article through our Network Security solutions, such as Advanced WildFire and Advanced URL Filtering, as well as our Cortex line of products.
If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Threat Hunting - Generic
- Block Indicators - Generic v3
- Rapid Breach Response - Set Incident Info
Integrations
This playbook does not use any integrations.
Scripts
- HttpV2
Commands
- extractIndicators
- createNewIndicator
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| PlaybookDescription | The playbook description to be used in the Rapid Breach Response - Set Incident Info sub-playbook. | A Russian threat actor we track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024. Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content. Unit 42 has previously observed other threat groups using this tactic. For example, in 2023, a different Russian threat group, Cloaked Ursa, repurposed an advertisement for a BMW for sale to target diplomatic missions within Ukraine. This campaign is not directly connected to the Fighting Ursa campaign described here. However, the similarity in tactics points to known behaviors of Fighting Ursa. The Fighting Ursa group is known for repurposing successful tactics – even continuously exploiting known vulnerabilities for 20 months after their cover was already blown. The details of the March 2024 campaign, which we attribute to Fighting Ursa with a medium to high level of confidence, indicate the group targeted diplomats and relied on public and free services to host various stages of the attack. This article examines the infection chain from the attack. Palo Alto Networks customers are better protected from the threats discussed in this article through our Network Security solutions, such as Advanced WildFire and Advanced URL Filtering, as well as our Cortex line of products. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. |
Optional |
| autoBlockIndicators | Whether to block the indicators automatically. | False | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
PlaybookDescription— The playbook description to be used in the Rapid Breach Response - Set Incident Info sub-playbook.autoBlockIndicators— Whether to block the indicators automatically.
Commands used
createNewIndicator
extractIndicators
Flowchart
id: Fighting Ursa Luring Targets With Car For Sale version: -1 name: Fighting Ursa Luring Targets With Car For Sale description: |- A Russian threat actor we track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024. Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content. Unit 42 has previously observed other threat groups using this tactic. For example, in 2023, a different Russian threat group, Cloaked Ursa, repurposed an advertisement for a BMW for sale to target diplomatic missions within Ukraine. This campaign is not directly connected to the Fighting Ursa campaign described here. However, the similarity in tactics points to known behaviors of Fighting Ursa. The Fighting Ursa group is known for repurposing successful tactics – even continuously exploiting known vulnerabilities for 20 months after their cover was already blown. The details of the March 2024 campaign, which we attribute to Fighting Ursa with a medium to high level of confidence, indicate the group targeted diplomats and relied on public and free services to host various stages of the attack. This article examines the infection chain from the attack. Palo Alto Networks customers are better protected from the threats discussed in this article through our Network Security solutions, such as Advanced WildFire and Advanced URL Filtering, as well as our Cortex line of products. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. starttaskid: "0" tasks: "0": id: "0" taskid: cd6d1aea-2177-4009-8a31-88ea7e5ecec5 type: start task: id: cd6d1aea-2177-4009-8a31-88ea7e5ecec5 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "1" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 240 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "1": id: "1" taskid: 2c1f252d-6fe7-4329-8b3c-141a9c8456c7 type: title task: id: 2c1f252d-6fe7-4329-8b3c-141a9c8456c7 version: -1 name: Download Detection Rules type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "3" - "95" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 415 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "3": id: "3" taskid: 78584de9-f13b-434d-8d34-6eb52ce2c5c7 type: regular task: id: 78584de9-f13b-434d-8d34-6eb52ce2c5c7 version: -1 name: Download APT APT28 rule description: |- This file contains multiple Yara rules provided by Neo23x0. Reference: https://raw.githubusercontent.com/Neo23x0/signature-base/master/yara/apt_apt28.yar tags: - Yara scriptName: HttpV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: filename: simple: YaraRule.yar method: simple: GET save_as_file: simple: "yes" unsecure: simple: "True" url: simple: https://raw.githubusercontent.com/Neo23x0/signature-base/master/yara/apt_apt28.yar separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 590 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "4": id: "4" taskid: 2d92d350-0ad4-4762-8110-5b905c3233ed type: title task: id: 2d92d350-0ad4-4762-8110-5b905c3233ed version: -1 name: Extract and Tag Indicators type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "5" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 765 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "5": id: "5" taskid: dda13c98-34a1-4a38-83d7-2d992f7bf91e type: regular task: id: dda13c98-34a1-4a38-83d7-2d992f7bf91e version: -1 name: Extract Indicators description: commands.local.cmd.extract.indicators script: Builtin|||extractIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "6" - "93" - "74" scriptarguments: text: simple: i.ibb.co, webhook.site, img-387470302099.zip, https://i.ibb.co/vVSCr2Z/car-for-sale.jpg, https://webhook.site/66d5b9f9-a5eb-48e6-9476-9b6142b0c3ae, https://webhook.site/d290377c-82b5-4765-acb8-454edf6425dd, 6b96b991e33240e5c2091d092079a440fa1bef9b5aecbf3039bf7c47223bdf96, a06d74322a8761ec8e6f28d134f2a89c7ba611d920d080a3ccbfac7c3b61e2e7, cda936ecae566ab871e5c0303d8ff98796b1e3661885afd9d4690fc1e945640e, 7c85ff89b535a39d47756dfce4597c239ee16df88badefe8f76051b836a7cbfb, dad1a8869c950c2d1d322c8aed3757d3988ef4f06ba230b329c8d510d8d9a027, c6a91cba00bf87cdb064c49adaac82255cbec6fdd48fd21f9b3b96abf019916b separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 940 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "6": id: "6" taskid: e61eb172-7a67-4b54-8ab3-31d9420bc776 type: regular task: id: e61eb172-7a67-4b54-8ab3-31d9420bc776 version: -1 name: Tag Domain indicators description: commands.local.cmd.new.indicator script: Builtin|||createNewIndicator type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "7" scriptarguments: retry-count: simple: "3" retry-interval: simple: "2" tags: simple: APT28 type: simple: Domain value: complex: root: ExtractedIndicators.Domain filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.Domain iscontext: true transformers: - operator: uniq separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 1115 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "7": id: "7" taskid: d7869f25-257d-4290-846e-1f3341b41b75 type: title task: id: d7869f25-257d-4290-846e-1f3341b41b75 version: -1 name: Set Response Layout type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "8" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 1290 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "8": id: "8" taskid: bfc7756d-a1db-4c5a-890d-a6f7820e8c21 type: playbook task: id: bfc7756d-a1db-4c5a-890d-a6f7820e8c21 version: -1 name: Rapid Breach Response - Set Incident Info description: This playbook is responsible for setting up the Alert Info tab in the layout. playbookName: Rapid Breach Response - Set Incident Info type: playbook iscommand: false brand: "" nexttasks: '#none#': - "9" scriptarguments: SourceOfIndicators: complex: root: http.parsedBlog accessor: sourceLink countTotalIndicators: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: append args: item: value: simple: ExtractedIndicators.IP iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.URL iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.File iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.CVE iscontext: true - operator: uniq - operator: count playbookDescription: complex: root: inputs.PlaybookDescription separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 1882.5, "y": 1465 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "9": id: "9" taskid: 374a5fe7-1b7a-4585-82c1-57dd7bc2d103 type: title task: id: 374a5fe7-1b7a-4585-82c1-57dd7bc2d103 version: -1 name: Threat Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "11" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 1640 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "11": id: "11" taskid: d43dd38e-0432-4218-8fc3-692f847a5eb8 type: title task: id: d43dd38e-0432-4218-8fc3-692f847a5eb8 version: -1 name: Indicators Hunting description: Whether to continue with the investigation or close it. type: title iscommand: false brand: "" nexttasks: '#none#': - "15" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 1815 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "14": id: "14" taskid: 92b01957-5d26-4799-8ff0-60448ae605e0 type: title task: id: 92b01957-5d26-4799-8ff0-60448ae605e0 version: -1 name: Remediation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "16" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 2165 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "15": id: "15" taskid: 0d3d0dd9-a200-4ab1-8cab-a6af94efaf7b type: playbook task: id: 0d3d0dd9-a200-4ab1-8cab-a6af94efaf7b version: -1 name: Threat Hunting - Generic description: "This playbook enables threat hunting for IOCs in your enterprise. It currently supports the following integrations: \n- Splunk\n- Qradar\n- Pan-os \n- Cortex Data Lake \n- Autofocus\n- Microsoft 365 Defender" playbookName: Threat Hunting - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "14" scriptarguments: IPAddress: complex: root: IP accessor: Address transformers: - operator: uniq InternalRange: complex: root: lists accessor: PrivateIPs transformers: - operator: RegexExtractAll args: error_if_no_match: {} ignore_case: {} multi_line: {} period_matches_newline: {} regex: value: simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2}) unpack_matches: {} - operator: join args: separator: value: simple: ',' MD5: complex: root: File accessor: MD5 SHA1: complex: root: File accessor: SHA1 SHA256: complex: root: File accessor: SHA256 URLDomain: complex: root: Domain accessor: Name transformers: - operator: append args: item: value: simple: URL.Data iscontext: true - operator: uniq separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 1882.5, "y": 1990 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "16": id: "16" taskid: 72ae092e-8747-4d08-8bbc-a055c5fc5092 type: condition task: id: 72ae092e-8747-4d08-8bbc-a055c5fc5092 version: -1 name: Should block indicators automatically? description: Checks whether to block the indicators automatically. type: condition iscommand: false brand: "" nexttasks: '#default#': - "17" "yes": - "18" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.autoBlockIndicators iscontext: true right: value: simple: "True" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 2340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "17": id: "17" taskid: c2323038-4a55-4257-89cb-d07888159b0a type: regular task: id: c2323038-4a55-4257-89cb-d07888159b0a version: -1 name: Handle indicators manually description: Manual task for indicators handling. type: regular iscommand: false brand: "" nexttasks: '#none#': - "19" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1660, "y": 2515 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "18": id: "18" taskid: e00d8739-b1dc-4381-8501-4cd13e4f946f type: playbook task: id: e00d8739-b1dc-4381-8501-4cd13e4f946f version: -1 name: Block Indicators - Generic v3 description: |- This playbook blocks malicious indicators using all integrations that are enabled, using the following sub-playbooks: - Block URL - Generic v2 - Block Account - Generic v2 - Block IP - Generic v3 - Block File - Generic v2 - Block Email - Generic v2 - Block Domain - Generic v2. playbookName: Block Indicators - Generic v3 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "19" scriptarguments: AutoBlockIndicators: simple: "True" AutoCommit: simple: "No" CustomBlockRule: simple: "True" CustomURLCategory: simple: XSOAR Remediation - Malicious URLs DomainToBlock: complex: root: Domain accessor: Name EmailToBlock: complex: root: DBotScore filters: - - operator: isEqualString left: value: simple: DBotScore.Type iscontext: true right: value: simple: email - - operator: greaterThanOrEqual left: value: simple: DBotScore.Score iscontext: true right: value: simple: "3" accessor: Indicator transformers: - operator: uniq FilesToBlock: complex: root: DBotScore filters: - - operator: isEqualString left: value: simple: DBotScore.Type iscontext: true right: value: simple: file - - operator: greaterThanOrEqual left: value: simple: DBotScore.Score iscontext: true right: value: simple: "3" accessor: Indicator transformers: - operator: uniq IP: complex: root: IP accessor: Address transformers: - operator: uniq InputEnrichment: simple: "False" InternalRange: complex: root: lists accessor: PrivateIPs transformers: - operator: RegexExtractAll args: error_if_no_match: {} ignore_case: {} multi_line: {} period_matches_newline: {} regex: value: simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2}) unpack_matches: {} - operator: join args: separator: value: simple: ',' MD5: complex: root: File accessor: MD5 transformers: - operator: uniq RuleDirection: simple: outbound RuleName: simple: XSOAR - Block Indicators playbook - 29 SHA256: complex: root: File accessor: SHA256 transformers: - operator: uniq Tag: simple: Blocked Indicator In Systems URL: complex: root: URL accessor: Data transformers: - operator: uniq UserVerification: simple: "True" Username: complex: root: DBotScore filters: - - operator: isEqualString left: value: simple: DBotScore.Type iscontext: true right: value: simple: username ignorecase: true - - operator: greaterThanOrEqual left: value: simple: DBotScore.Score iscontext: true right: value: simple: "3" accessor: Indicator transformers: - operator: uniq separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 2102.5, "y": 2515 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "19": id: "19" taskid: e1b0fc7e-7e60-46ff-8edc-da0c37893d15 type: title task: id: e1b0fc7e-7e60-46ff-8edc-da0c37893d15 version: -1 name: Mitigation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "20" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 2690 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "20": id: "20" taskid: 855939f6-af29-4205-8a9c-bb426d668a5d type: regular task: id: 855939f6-af29-4205-8a9c-bb426d668a5d version: -1 name: Unit42 recommended workarounds description: |- Palo Alto Networks customers are better protected from the threats discussed above through the following products: Cortex XDR detects the attack chain described, among other protections in the Cortex XDR platform. Advanced URL Filtering identifies known URLs associated with this activity as malicious. The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the IoCs shared in this research. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America Toll-Free: 866.486.4842 (866.4.UNIT42) EMEA: +31.20.299.3130 APAC: +65.6983.8730 Japan: +81.50.1790.0200 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. type: regular iscommand: false brand: "" nexttasks: '#none#': - "21" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 2865 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "21": id: "21" taskid: 0551b9e3-9264-4b8e-8ff1-ff135a15c0fa type: title task: id: 0551b9e3-9264-4b8e-8ff1-ff135a15c0fa version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1882.5, "y": 3040 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "74": id: "74" taskid: 4df41254-0dfc-4525-8da5-74ce17d75e17 type: regular task: id: 4df41254-0dfc-4525-8da5-74ce17d75e17 version: -1 name: Tag File indicators description: commands.local.cmd.new.indicator script: Builtin|||createNewIndicator type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "7" scriptarguments: retry-count: simple: "3" retry-interval: simple: "2" tags: simple: APT28 type: simple: File value: complex: root: ExtractedIndicators.File filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.Domain iscontext: true transformers: - operator: uniq separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 2682.5, "y": 1115 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "93": id: "93" taskid: ddc9c956-c62f-43dc-8a44-290cfcae8f05 type: regular task: id: ddc9c956-c62f-43dc-8a44-290cfcae8f05 version: -1 name: Tag URL indicators description: commands.local.cmd.new.indicator script: Builtin|||createNewIndicator type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "7" scriptarguments: retry-count: simple: "3" retry-interval: simple: "2" tags: simple: APT28 type: simple: URL value: complex: root: ExtractedIndicators.URL filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.Domain iscontext: true transformers: - operator: uniq separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 2282.5, "y": 1115 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "95": id: "95" taskid: 401f46ab-fa8a-4f94-84de-9b7cc2741b05 type: regular task: id: 401f46ab-fa8a-4f94-84de-9b7cc2741b05 version: -1 name: Download APT APT28 drovorub rule description: |- This file contains multiple Yara rules provided by Neo23x0. Reference: https://raw.githubusercontent.com/Neo23x0/signature-base/master/yara/apt_apt28_drovorub.yar tags: - Yara scriptName: HttpV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: filename: simple: YaraRule.yar method: simple: GET save_as_file: simple: "yes" unsecure: simple: "True" url: simple: https://raw.githubusercontent.com/Neo23x0/signature-base/master/yara/apt_apt28_drovorub.yar separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 2282.5, "y": 590 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 2865, "width": 1402.5, "x": 1660, "y": 240 } } } inputs: - key: PlaybookDescription value: simple: |- A Russian threat actor we track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024. Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT). Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content. Unit 42 has previously observed other threat groups using this tactic. For example, in 2023, a different Russian threat group, Cloaked Ursa, repurposed an advertisement for a BMW for sale to target diplomatic missions within Ukraine. This campaign is not directly connected to the Fighting Ursa campaign described here. However, the similarity in tactics points to known behaviors of Fighting Ursa. The Fighting Ursa group is known for repurposing successful tactics – even continuously exploiting known vulnerabilities for 20 months after their cover was already blown. The details of the March 2024 campaign, which we attribute to Fighting Ursa with a medium to high level of confidence, indicate the group targeted diplomats and relied on public and free services to host various stages of the attack. This article examines the infection chain from the attack. Palo Alto Networks customers are better protected from the threats discussed in this article through our Network Security solutions, such as Advanced WildFire and Advanced URL Filtering, as well as our Cortex line of products. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. required: false description: The playbook description to be used in the Rapid Breach Response - Set Incident Info sub-playbook. playbookInputQuery: - key: autoBlockIndicators value: simple: "False" required: false description: Whether to block the indicators automatically. playbookInputQuery: outputs: [] tests: - No tests (auto formatted) fromversion: 6.10.0