Validin Uses Infrastructure Pivots to Track Russian Cyber Espionage Clusters

· Original article ↗

Summary

Validin analyzes domains and hosting linked to Russian cyber espionage clusters, using historical DNS, registration data, HTTP responses, certificates, and other pivots to identify candidate infrastructure and explain confidence limits.

Key points

  • The analysis builds on Google Threat Intelligence Group reporting about Russian espionage clusters targeting people in academia, think tanks, and other organizations in Europe and the United States.
  • For UNC6293, Validin linked two additional domains to a registrant email associated with a known lure domain; the relationships are presented as candidate infrastructure, not confirmed attribution.
  • HTML and CSS similarities, possible origin IPs, and host responses indicating possible Evilginx configurations provided further infrastructure pivots.
  • For UNC7005, DNS history connected a phishing domain to related infrastructure, while changes in server headers suggested one IP may have changed hands.
  • Title and header-hash searches, favicon hashes, certificates, and registration similarities surfaced additional domains, with filtering used to separate stronger candidates from likely incidental overlaps.
  • The article cautions that many identified domains and IPs may be unrelated and recommends validating candidate links and monitoring low-confidence registration pivots.

Article Details

Attack Vectors
  • UNC6293 used foreignrelations[.]us and dosportal[.]app as lures for OAuth phishing.
  • UNC7005 reportedly used Microsoft device-code phishing and device-code phishing targeting WhatsApp accounts.
  • my-invite[.]org facilitated phishing through links in email.
  • statistic-ms[.]live redirected visitors to an Ad Manager login prompt at https[:]//ad-g[.]org/login.
  • UNC5976 used drive[.]google[.]verify-drive[.]com in an OAuth phishing campaign.
  • Several subdomains of stateaffairs[.]us and the-washington-ballet[.]com showed possible Evilginx configurations and redirected visitors to legitimate websites.
Defensive Notes
  • Use historical DNS, host responses, certificates, registration records, HTTP headers, CSS similarities, and favicon hashes to identify and evaluate related infrastructure.
  • Treat infrastructure discovered through pivots as candidates requiring verification; the article notes that some overlaps may be incidental or unrelated.
  • Monitor the low-confidence registration-pivot domains supportnoreplay[.]com, security-forms[.]com, noreplaysupport[.]com, and info-forms[.]com for future use.

Indicators of compromise

TypeIndicatorContext
DOMAINdosportal[.]appUNC6293-associated domain used as an OAuth phishing lure.
DOMAINdrive[.]google[.]anticorruption[.]eurcpa[.]orgListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]formshare[.]cloudListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]linkfileshare[.]netDomain identified via registration pivot and listed as a suspected campaign-related phishing indicator.
DOMAINdrive[.]google[.]sharedfolders[.]appListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]sharedfolders[.]orgListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]sharefolders[.]orgListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]usercontent[.]appListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]usercontent[.]onlineListed as suspected campaign-related phishing infrastructure with hosting and content similarities.
DOMAINdrive[.]google[.]verify-drive[.]comDomain used in an OAuth phishing campaign attributed by GTIG to UNC5976.
DOMAINeurcpa[.]orgListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINfileshareapp[.]orgNet-new domain listed as suspected campaign-related infrastructure with valid certificates and similar HTTP content.
DOMAINfllefolder[.]comListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINforeignrelations[.]usUNC6293-associated domain used as an OAuth phishing lure.
DOMAINformshare[.]cloudListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINinfo-forms[.]comLow-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed.
DOMAINinternationalaffairsportal[.]usDomain associated by registrant email and registration timing with UNC6293-associated infrastructure; listed as a suspected related indicator.
DOMAINlinkfileshare[.]netDomain identified via registration pivot and listed as a suspected campaign-related indicator.
DOMAINms365-live[.]comRelated domain sharing DNS-history overlap with the IP address used by my-invite[.]org.
DOMAINmy-invite[.]orgActor-controlled domain reported by GTIG as facilitating phishing through email links.
DOMAINnoreplaysupport[.]comLow-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed.
DOMAINsecurity-forms[.]comLow-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed.
DOMAINsharedfolders[.]appListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINsharedfolders[.]orgListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINsharefolders[.]orgListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINstateaffairs[.]usDomain associated by registrant email and registration timing with UNC6293-associated infrastructure; subdomains showed possible Evilginx configuration.
DOMAINstatistic-ms[.]liveDomain that redirected visitors to a login prompt at ad-g[.]org.
DOMAINsupportnoreplay[.]comLow-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed.
DOMAINthe-washington-ballet[.]comLookalike domain with possible Evilginx configuration and infrastructure similarities to the dosportal[.]app decoy.
DOMAINusercontent[.]appListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINusercontent[.]onlineListed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster.
DOMAINverify-drive[.]comDomain associated with the drive[.]google[.]verify-drive[.]com phishing infrastructure.
IPV4104[.]194[.]159[.]150IP address to which the phishing domain my-invite[.]org resolved.
IPV4151[.]236[.]15[.]213Possible origin IP for Cloudflare-fronted domains with CSS similarities to the dosportal[.]app decoy.
IPV4185[.]158[.]250[.]155Possible origin IP for Cloudflare-fronted domains with CSS similarities to the dosportal[.]app decoy.
URLhxxps[:]//ad-g[.]org/loginLogin-prompt URL to which statistic-ms[.]live redirected visitors.

MITRE ATT&CK

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles