Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FlyingYeti

Also known as: Storm-1837, Flying Yeti, the threat actor, SkyCloak

Description

FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using malware like COOKBOX. FlyingYeti exploits the WinRAR vulnerability CVE-2023-38831 to infect targets with malicious payloads. Cloudforce One has successfully disrupted their operations and provided recommendations for defense against their phishing campaigns.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Energy
Critical infrastructure
Hospitality
Telecommunications
Education
Utilities
Non profit
Media
Gaming
Nuclear
Think tank
Legal services
Maritime
Retail
Pharmaceutical
Mining

Targeted Countries / Regions

UA
RU
CN
IR
IN
GB
KP
PL
KR
JP
IL
IT
CA
SG
RO
US
TR
ES
MX
FR
TW

AI Analysis

· 1 week ago

Executive Summary

FlyingYeti, also known as Storm-1837 or Flying Yeti, is a Russia-aligned cyber threat actor primarily targeting Ukrainian military entities. The group conducts reconnaissance and phishing campaigns, leveraging the CVE-2023-38831 WinRAR vulnerability to deploy malware such as COOKBOX. Their activities pose significant risks to national security infrastructure.

Goals & Targeting

FlyingYeti appears to be targeting Ukrainian military entities with the likely goal of gathering intelligence or disrupting operations. Their strategic objectives may include undermining Ukraine's national security capabilities or supporting broader Russian geopolitical interests in the region. The group focuses on military targets, suggesting a focus on espionage or sabotage rather than purely financial gain.

Enhanced Description

FlyingYeti is a cyber threat actor aligned with Russian interests, focusing on Ukrainian military and defense sector targets. The group has been observed conducting reconnaissance missions and executing phishing campaigns using malicious payloads delivered via exploit of the CVE-2023-38831 WinRAR vulnerability. This technique allows them to infiltrate systems and deploy COOKBOX malware, highlighting their ability to exploit known vulnerabilities for strategic advantage. FlyingYeti's operations have been disrupted by Cloudforce One, which has provided actionable defense recommendations against their phishing campaigns. The group's tactics demonstrate a focus on compromising sensitive military information through targeted and technically sophisticated attacks.

Key Capabilities

  • Phishing campaigns using malicious links
  • Exploitation of WinRAR vulnerability (CVE-2023-38831)
  • Deployment of COOKBOX malware
  • Reconnaissance activities targeting military infrastructure

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1059
T1055
T1566
T1203

Software / Tooling

COOKBOX malware
Custom phishing tools

Campaigns & Victims

FlyingYeti has demonstrated a focused approach to targeting Ukrainian military entities, with campaigns characterized by spear-phishing emails and exploit-based attacks. Their recent operations suggest an emphasis on compromising sensitive systems and exfiltrating or disrupting data. Notable past activities include the successful deployment of COOKBOX malware following WinRAR vulnerability exploitation.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Exploitation of CVE-2023-38831 in WinRAR
  • Malware signatures associated with COOKBOX

Recommended Actions

  • Implement multi-factor authentication for sensitive systems.
  • Monitor for phishing attempts targeting military personnel.
  • Apply patches for known vulnerabilities like CVE-2023-38831.
  • Use email filtering to detect and block malicious links.

Suggested Tags

APT
espionage
military
Ukraine

Confidence Assessment

High confidence in the data regarding FlyingYeti's targeting of Ukrainian military entities and use of COOKBOX malware, as well as the CVE-2023-38831 vulnerability. However, specific details about their primary motivation and long-term strategic goals remain uncertain due to limited open-source reporting on their activities.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 1 Domain 12 URL 6 SHA-256 Hash 1

References

  1. www.varutra.com — Cited by web research for: SkyCloak
  2. learn.microsoft.com — Cited by web research for: Global
  3. www.microsoft.com — Cited by web research for: ClickFix
  4. blog.cloudflare.com — Cited by web research for: postdock.serveftp.com

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Government Targeting
APT
espionage
military
Ukraine

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.