, 9 tweets, 3 min read
My Authors
Read all threads
So just to be explicit about our research @ThreatConnect, we initially came across the cubenergy-my-sharepoint[.]com by exploiting some consistencies that we've seen in previous Fancy Bear infrastructure.
To be specific, the use of a PositiveSSL certificate in conjunction with a Sharepoint-related string, has been used several times previously by Fancy Bear and not widely seen elsewhere.
Notably, that was seen in several of the Fancy Bear domains spoofing NGOs that Microsoft sinkholed earlier this year, like soros-my-sharepoint[.]com and transparencyinternational-my-sharepoint[.]com.
That cubenergy-my-sharepoint[.]com domain lead to another, dpkshodnya-my-sharepoint[.]com, by way of some initial redirect information. That domain also has that PositiveSSL certificate and Sharepoint string consistency.
That domain was initially registered using a barid[.]com email address. I then reviewed barid[.]com email registered domains using name servers that Fancy Bear has previously consistently used (like ITitch) and found those additional kub-gas[.]com and kvatral95[.]com domains.
Ultimately, none of these characteristics are definitively indicative of APT28 activity and we don't have any specific information on how the domains have been operationalized.
However, considering the possible targets that the domains spoof and given the aforementioned non-definitive consistencies, we assess with moderate confidence that the domains probably are associated with APT28 operations.
More information on how and against whom the identified infrastructure was operationalized could ultimately strengthen our assessment and increase our confidence in that attribution.
Should have included this originally, but this research leveraged capabilities from @DomainTools, @censysio, @urlscanio, @FarsightSecInc, and @PassiveTotal. Many thanks to you all for enabling this research.
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Kyle Ehmke

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!