RedStinger (Bad Magic) targets government, agriculture, and transportation entities in Donetsk, Lugansk, and Crimea regions.
Analyst brief
RedStinger (also known as Bad Magic) is a threat actor of unknown type. It primarily targets government, agriculture, and transportation organizations in the Donetsk, Lugansk, and Crimea regions. The main TTP involves likely using spear phishing to deliver a URL pointing to a ZIP archive hosted on a malicious web server. Defenders should monitor traffic to suspicious URLs, train users to avoid phishing emails, and monitor systems for suspicious downloads from archive files.
RedStinger
Bad Magic
unknown
In October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crimea regions. Although the initial vector of compromise is unclear, the details of the next stage imply the use of spear phishing or similar methods. The victims navigated to a URL pointing to a ZIP archive hosted on a malicious web server.