APT29 Targets French and European Diplomatic Entities in Persistent Cyberattacks – Active IOCs – Rewterz

ANSSI reports that Russia-linked APT29 (Nobelium/Cozy Bear) has been targeting French diplomatic entities through credential phishing and forged documents in the so-called Diplomatic Orbiter campaign, potentially aiming to gather strategic intelligence. The attackers deploy loaders to drop post-exploitation tools such as Cobalt Strike or Brute Ratel C4 to gain network access, move laterally, persist, and exfiltrate data, with indicators including specific domains, hashes, and URLs. #APT29 #Nobelium #CozyBear #DarkHalo #DiplomaticOrbiter #CobaltStrike #BruteRatel #ANSSI

Keypoints

  • ANSSI links Russia-based APT29 (Nobelium/Cozy Bear) to attacks on French diplomatic entities, using compromised staff accounts for phishing.
  • The campaign, named “Diplomatic Orbiter,” involves forging lure documents to target diplomatic staff.
  • Attackers deliver loaders to drop post-exploitation tools (e.g., Cobalt Strike, Brute Ratel C4) to enable network access, lateral movement, persistence, and exfiltration.
  • Recent activity indicates APT29 has targeted Western diplomatic entities and some IT companies in 2023–2024, with multiple phishing incidents involving French state actors.
  • Notable incidents include phishing from compromised accounts of French institutions (e.g., Ministry of Culture, ANCT) and attacks on European embassies in Kyiv and elsewhere.
  • IOCs include domains, file hashes, and URLs such as siestakeying.com, waterforvoiceless.org, and several hash values and web addresses.
  • Remediation emphasizes blocking indicators, patching email servers, 2FA, network segmentation, and regular backups to limit impact.

MITRE Techniques

  • [T1566.001] Phishing – Phishing campaigns aimed at French public and diplomatic entities to gather strategic intelligence. Quote: “phishing campaigns aimed at French public and diplomatic entities to gather strategic intelligence.”
  • [T1078] Valid Accounts – Using compromised legitimate email accounts of diplomatic staff to conduct phishing campaigns against diplomatic institutions. Quote: “using compromised legitimate email accounts of diplomatic staff to conduct phishing campaigns against diplomatic institutions.”
  • [T1036] Masquerading – Forging lure documents to target diplomatic staff. Quote: “a method called the ‘Diplomatic Orbiter’ campaign involves attackers forging lure documents to target diplomatic staff.”
  • [T1105] Ingress Tool Transfer – Delivering custom loaders to drop post-exploitation tools like Cobalt Strike or Brute Ratel C4. Quote: “to deliver custom loaders to drop post-exploitation tools like Cobalt Strike or Brute Ratel C4.”
  • [T1021] Remote Services – Enabling lateral movements, payload deployment, persistence, and intelligence exfiltration within networks. Quote: “enabling network access, lateral movements, payload deployment, persistence, and intelligence exfiltration.”

Indicators of Compromise

  • [Domain] context – siestakeying.com, waterforvoiceless.org
  • [MD5] context – 8bd528d2b828c9289d9063eba2dc6aa0, efafcd00b9157b4146506bd381326f39, and 1 more hash
  • [SHA-256] context – d0a8fa332950b72968bdd1c8a1a0824dd479220d044e8c89a7dea4434b741750, a0f183ea54cb25dd8bdba586935a258f0ecd3cba0d94657985bb1ea02af8d42c, and 1 more hash
  • [SHA-1] context – 5d3f3113ef76af7c1a2447d35e8b09bd270b461e, 5b6b25012fa541a227e1c20d9f3004ce4e7d4aee
  • [URL] context – https://siestakeying.com/auth.php, https://waterforvoiceless.org/util.php, https://waterforvoiceless.org/invite.php

Read more: https://www.rewterz.com/threat-advisory/apt29-targets-french-and-european-diplomatic-entities-in-persistent-cyberattacks-active-iocs