Operation Poison NeedlesOperation Poison Needles

Also known as: Operation Poison Needles

Known aliases
1

Profile

What’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution was established in 1965 and it was founded by the Presidential Administration of Russia. The multidisciplinary outpatient institution mainly serves the civil servants of the highest executive, legislative, judicial authorities of the Russian Federation, as well as famous figures of science and art. Since it is the first detection of this APT attack by 360 Security on a global scale, we code-named it as “Operation Poison Needles”, considering that the target was a medical institution. Currently, the attribution of the attacker is still under investigation. However, the special background of the polyclinic and the sensitiveness of the group it served both indicate the attack is highly targeted. Simultaneously, the attack occurred at a very sensitive timing of the Kerch Strait Incident, so it also aroused the assumption on the political attribution of the attack.

Aliases· 1

Operation Poison Needles

References

  1. http://blogs.360.cn/post/PoisonNeedles_CVE-2018-15982_EN

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
People's Cyber Army of Russia
Actor
Operation Parliament
Actor
APT29
Actor
Operation ForumTroll
Actor
APT2
Group
APT28
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.