ELBRUS is an advanced persistent threat (APT) that has been active since at least 2014, targeting government agencies and organizations in various countries including Russia, Ukraine, Belarus, and Kazakhstan. It is believed to be operated by Russian state-sponsored hackers known as Fancy Bear or APT28. ELBRUS uses a variety of tactics such as spear phishing emails, watering hole attacks, and exploiting vulnerabilities in software to gain access to its targets\' networks. Once inside the network, it can steal sensitive information, install backdoors for future access, and perform other malicious activities.
Techniques, tactics and practices:
ELBRUS uses a variety of tactics such as spear phishing emails, watering hole attacks, and exploiting vulnerabilities in software to gain access to its targets\' networks. Once inside the network, it can steal sensitive information, install backdoors for future access, and perform other malicious activities.
