FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities with COOKBOX malware.
Analyst brief
FlyingYeti (also tracked as Storm-1837) is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance and launch phishing campaigns to deliver the COOKBOX malware, exploiting the WinRAR vulnerability CVE-2023-38831 for initial infection. Defenders should prioritize awareness of military-themed phishing lures, patch CVE-2023-38831 immediately, and monitor for network indicators linked to COOKBOX C2 activity.
FlyingYeti
Storm-1837Flying Yeti
unknown
FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using malware like COOKBOX. FlyingYeti exploits the WinRAR vulnerability CVE-2023-38831 to infect targets with malicious payloads. Cloudforce One has successfully disrupted their operations and provided recommendations for defense against their phishing campaigns.
Which malware does FlyingYeti deliver by exploiting the WinRAR vulnerability?+
FlyingYeti exploits the WinRAR vulnerability CVE-2023-38831 to deploy the COOKBOX malware.
What are the primary defensive measures against the FlyingYeti threat actor?+
Defenders should prioritize awareness of military-themed phishing lures, apply patches for CVE-2023-38831, and monitor for network indicators linked to COOKBOX C2 activity.