REF7707 is a cyber espionage group targeting South American government entities using FinalDraft and GuidLoader malware.
Analyst brief
REF7707 is a cyber espionage campaign targeting a foreign ministry in South America, focusing on government entities. The actor leverages malware families like FinalDraft, GuidLoader, and PathLoader for persistence and lateral movement, while utilizing Microsoft Graph API for C2 communication to blend into legitimate traffic. Defenders should monitor for anomalous Microsoft Graph API activity and unusual endpoint queries, as the threat actor aims to extract sensitive data such as passwords and Active Directory information.
REF7707
CL-STA-0049Jewelbug
activeunknown
REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families such as FinalDraft, GuidLoader, and PathLoader for persistence and lateral movement. The threat actor employs the Microsoft Graph API for C2 communication, blending malicious traffic with legitimate activity to evade detection. Despite their technical sophistication, REF7707 operators exhibited poor operational security, leading to the exposure of their infrastructure and malware. Their tactics enable the extraction of sensitive data, including passwords and Active Directory information, facilitating ongoing espionage activities.