Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Poison Needles

Operation Poison Needles

TLP:CLEAR
Active

Description

What’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution was established in 1965 and it was founded by the Presidential Administration of Russia. The multidisciplinary outpatient institution mainly serves the civil servants of the highest executive, legislative, judicial authorities of the Russian Federation, as well as famous figures of science and art. Since it is the first detection of this APT attack by 360 Security on a global scale, we code-named it as “Operation Poison Needles”, considering that the target was a medical institution. Currently, the attribution of the attacker is still under investigation. However, the special background of the polyclinic and the sensitiveness of the group it served both indicate the attack is highly targeted. Simultaneously, the attack occurred at a very sensitive timing of the Kerch Strait Incident, so it also aroused the assumption on the political attribution of the attack.

AI Analysis

· 1 week ago

Executive Summary

Operation Poison Needles is a suspected advanced persistent threat (APT) targeting a sensitive medical institution in Russia, potentially linked to state-sponsored activity. The attack was notable for its timing during the Kerch Strait Incident and its highly targeted approach to compromising an organization with ties to Russian executive and legislative authorities.

Goals & Targeting

The primary objective appears to be compromising sensitive information from a highly protected medical institution serving influential figures in Russia. The targeting of such a specific, high-value organization suggests a focus on intelligence gathering or disruption of state-related activities. Potential long-term goals may include embarrassing the Russian government or influencing geopolitical dynamics.

Enhanced Description

Operation Poison Needles represents a cyberattack campaign attributed to a yet-unidentified actor that compromised a high-profile polyclinic in Russia. The attack targeted an institution established in 1965, associated with the Presidential Administration of Russia, and serving civil servants from executive, legislative, and judicial authorities, as well as prominent figures in science and art. This indicates a highly targeted operation, possibly driven by espionage or disruption motives. Given the timing of the attack during the Kerch Strait Incident, there are speculative links to potential political or state-sponsored adversaries. The campaign's sophistication suggests involvement of an advanced actor with access to significant resources and intent to compromise sensitive information.

Key Capabilities

  • Spear-phishing with malicious Office documents
  • Compromise of web infrastructure
  • Highly targeted attack methodology

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom malware (inferred from campaign patterns)
Spear-phishing tools
living-off-the-land behavior

Campaigns & Victims

Operation Poison Needles demonstrates a patient and targeted approach to compromising sensitive systems. The attack's timing during the Kerch Strait Incident suggests possible关联性with broader geopolitical events. Future operations may target similar high-value institutions in politically sensitive sectors, leveraging sophisticated methods to avoid detection.

IOC Patterns

  • Spear-phishing emails targeting medical or government employees
  • Malicious Office documents attached to phishing emails
  • Unusual network activity from compromised systems

Recommended Actions

  • Monitor for spear-phishing attempts with malicious Office attachments
  • Enhance email security measures with tools like Microsoft 365 Defender
  • Conduct regular audits of web infrastructure for vulnerabilities
  • Implement strict access controls for sensitive medical data

Suggested Tags

APT
espionage
nation-state
healthcare

Confidence Assessment

Low to medium confidence in exact attribution due to limited details, though clear indicators suggest a state-sponsored actor. Techniques and TTPs align with known APT behaviors, but further data on specific tools or additional victimology would strengthen the analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Healthcare Targeting
espionage
nation-state
healthcare

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.