Custom PowerShell scripts are being deployed against geofenced targets in Australia, Belgium, and Poland to exfiltrate data.

Dark Reading Staff, Dark Reading

September 11, 2023

1 Min Read
Man stealing in business concept image
Source: Anna Berkut via Alamy

A sophisticated cyber campaign is using images of OnlyFans models and geofencing to target specific victims across Australia, Poland, and Belgium, using custom PowerShell scripts to steal data.

According to a recent report from Zscaler ThreatLabz, the campaign, called "Steal-It," is likely the work of APT28, also known as Fancy Bear, researchers said.

After establishing an initial foothold with customized PowerShell Nishang Start-CaptureServer scripts, the Steal-It cyberattack abuses the Mockbin API endpoint generating tool to exfiltrate data, including NTLM hashes and command output, the report explained.

"These operations use customized PowerShell scripts, designed to pilfer crucial NTLM hashes before transmitting it to the Mockbin platform," the researchers said. "The initial phase of the campaign involves the deployment of LNK files concealed in zip archives, while ensuring persistence within the system through strategic utilization of the StartUp folder."

The Fancy Bear threat group gained notoriety following its role in the 2016 US election interference and similarly used images of women as lures for cyberattacks against a Ukrainian energy facility earlier this month.

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like

More Insights