
5/30/2024 · Cloudforce One
What this post added
This post details Cloudforce One's proactive disruption of the FlyingYeti phishing campaign targeting Ukraine. It describes the campaign's background, including the use of debt-themed lures and the COOKBOX PowerShell malware, and the exploitation of the WinRAR vulnerability CVE-2023-38831. The post outlines the technical details of the attack infrastructure, including the use of Cloudflare Workers and GitHub, and the analysis of the malicious RAR file. It also details the countermeasures taken by Cloudforce One, such as remediating the actor-associated Worker and developing detections, which significantly prolonged the actor's operational timeline and prevented them from achieving their objectives.