3 Russian Threat Groups Target Persons of Interest

3 Russian Threat Groups Target Persons of Interest
GTIG reported on three Russian threat groups—UNC6293, UNC7005, and UNC5976—while the analysis identified 33 network IoCs and uncovered risky subdomains, typosquatting domains, and malicious infrastructure linked to the campaign. Additional DNS and WHOIS investigation revealed victim-related IP communications, email-connected domains, and weaponized domains such as dsapdlqpwd[.]icu. #UNC6293 #UNC7005 #UNC5976 #globsecnet #wa-connectnet #miov2iaiaoubqosiqoiajwowiwjsoonline #dsapdlqpwdicu

Keypoints

  • GTIG published a report on three Russian threat groups: UNC6293, UNC7005, and UNC5976.
  • The initial set of 32 network IoCs was refined to 33 total IoCs after extracting two subdomains into domains and removing legitimate company infrastructure.
  • One subdomain, drive[.]google[.]verify-drive[.]com, was assessed as high risk because it impersonated Google Drive.
  • Another subdomain, mail[.]kiis[.]co[.]uk, was rated moderately risky due to prior reputation and email-only configuration.
  • Domain analysis found wa-connect[.]net in a typosquatting cluster and miov2iaiaoubqosiqoiajwowiwjso[.]online on a malicious domain feed shortly after registration.
  • DNS and traffic analysis showed 317 unique potentially victim-owned IPs communicating with five IP IoCs, plus 2,494 email-connected domains discovered through reverse WHOIS.
  • Three email-connected domains were confirmed malicious, including dsapdlqpwd[.]icu, which was linked to malware distribution.

MITRE Techniques

  • [T1583.001] Acquire Infrastructure: Domains – The actors used newly registered and suspicious domains to support their infrastructure, including impersonation and typosquatting activity (‘brand new’, ‘typosquatting group’, ‘malicious intent’).
  • [T1584.001] Compromise Infrastructure: Domains – Malicious-looking domains were hosted and reused in ways that suggest operational infrastructure for the campaign (‘co-hosted with Google-mimicking domains’, ‘recorded 614 historical domain-to-IP resolutions’).
  • [T1036] Masquerading – The subdomain drive[.]google[.]verify-drive[.]com was crafted to impersonate Google Drive (‘deceptive subdomain labeling … to impersonate Google Drive’).
  • [T1566] Phishing – The use of impersonation, lookalike domains, and email-focused infrastructure suggests phishing-style delivery and lures (’email-only via registrar forwarding’, ‘lookalikes’).
  • [T1071.004] Application Layer Protocol: DNS – DNS was used extensively for resolution tracking and communication between clients, domains, and IPs (‘two DNS queries’, ‘domain-to-IP resolutions’, ‘IP-to-domain resolutions’).
  • [T1588.005] Obtain Capabilities: Exploits – A malicious domain was associated with malware distribution, indicating delivery of harmful payloads (‘associated with malware distribution’).

Indicators of Compromise

  • [Domains/Subdomains] Suspicious and malicious infrastructure identified in the report – drive[.]google[.]verify-drive[.]com, mail[.]kiis[.]co[.]uk, globsec[.]net, wa-connect[.]net, miov2iaiaoubqosiqoiajwowiwjso[.]online, dsapdlqpwd[.]icu, and other 20 domains
  • [IP Addresses] IP infrastructure linked to the campaign and observed in DNS/traffic analysis – 104[.]194[.]159[.]150, plus 4 other IP addresses
  • [Email Addresses] Historical WHOIS and reverse-WHOIS pivots used to discover related infrastructure – 34 unique historical email addresses, 9 public email addresses
  • [ASNs] Networks associated with potentially victim-owned communications to the IP IoCs – 23 distinct ASNs
  • [DNS Resolutions] Historical domain and IP resolution records used to map infrastructure – 614 domain-to-IP resolutions, 437 IP-to-domain resolutions
  • [Typosquatting Cluster] Lookalike domain set tied to wa-connect[.]net – kmconnect[.]online, pmo-connect[.]com, ut-connect[.]net, and 7 other lookalike domains


Read more: https://circleid.com/posts/3-russian-threat-groups-target-persons-of-interest