Unfortunately the IOC file is no longer hosted there. Luckily our friends at AT&T (Alienvault OTX) pulled the IOCs back when that blog was posted: otx.alienvault.com/pulse/54c7e1e8…
First look at IOCs alone is the domain mrbasic[.]com. However thats just dyndns and used by many unrelated actors over the years. mrbasic[.]com subdomains should not be considered related.
BTW these dates are basic on earliest public ver (VT mostly)
So again this is just VT, and well.. your telemetry may tell a different story, but UAC-0026 has been pushing around HeaderTip since at least Sept. 2020, with clues to something happening early-mid 2021 with them too.
What is "IMPC" and why would I want to join it in sept 2020?
15/x:
IDK I'm just guessing here but:
International Mineral Processing Congress?
Anyways here is the C2 from the the other HeaderTip sample above: dynamic.ddns[.]mobi
16/x:
That dynamic.ddns[.]mobi brings us to yet another pivot. This time back to 2018:
b5f2cc8e8580a44a6aefc08f9776516a
Which brings us to Scarab known infra from the Symantec blog at the top of this thread. Didn't expect that!
17/x:
So TLDR: UAC-0026 is indeed #Scarab APT. Disregard my previous comment on them not being the same.
1aba36f72685c12e60fb0922b606417c, March 2022
675ea1e99cbb9699dd4434aa54c3504c, June 2021
8cbff18f49c3ca0a98309070f6533967, May 2021
e4c38e8aaea8a1120127031ccfcfe7d6, March 2021
acd062593f70c00e310c47a3e7873df4, Sept 2020
19/19: Closing remarks:
As expected, CN isn’t far behind on spying in Ukraine.
ME is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
Targets and known victims include those involved in the Bhima Koregaon case, in which the evidence presented in the case was planted by the actor prior to arrests.