Also known as: Storm-1837, Flying Yeti, the threat actor, SkyCloak
FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using malware like COOKBOX. FlyingYeti exploits the WinRAR vulnerability CVE-2023-38831 to infect targets with malicious payloads. Cloudforce One has successfully disrupted their operations and provided recommendations for defense against their phishing campaigns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
FlyingYeti, also known as Storm-1837 or Flying Yeti, is a Russia-aligned cyber threat actor primarily targeting Ukrainian military entities. The group conducts reconnaissance and phishing campaigns, leveraging the CVE-2023-38831 WinRAR vulnerability to deploy malware such as COOKBOX. Their activities pose significant risks to national security infrastructure.
Goals & Targeting
FlyingYeti appears to be targeting Ukrainian military entities with the likely goal of gathering intelligence or disrupting operations. Their strategic objectives may include undermining Ukraine's national security capabilities or supporting broader Russian geopolitical interests in the region. The group focuses on military targets, suggesting a focus on espionage or sabotage rather than purely financial gain.
Enhanced Description
FlyingYeti is a cyber threat actor aligned with Russian interests, focusing on Ukrainian military and defense sector targets. The group has been observed conducting reconnaissance missions and executing phishing campaigns using malicious payloads delivered via exploit of the CVE-2023-38831 WinRAR vulnerability. This technique allows them to infiltrate systems and deploy COOKBOX malware, highlighting their ability to exploit known vulnerabilities for strategic advantage. FlyingYeti's operations have been disrupted by Cloudforce One, which has provided actionable defense recommendations against their phishing campaigns. The group's tactics demonstrate a focus on compromising sensitive military information through targeted and technically sophisticated attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FlyingYeti has demonstrated a focused approach to targeting Ukrainian military entities, with campaigns characterized by spear-phishing emails and exploit-based attacks. Their recent operations suggest an emphasis on compromising sensitive systems and exfiltrating or disrupting data. Notable past activities include the successful deployment of COOKBOX malware following WinRAR vulnerability exploitation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the data regarding FlyingYeti's targeting of Ukrainian military entities and use of COOKBOX malware, as well as the CVE-2023-38831 vulnerability. However, specific details about their primary motivation and long-term strategic goals remain uncertain due to limited open-source reporting on their activities.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics