Also known as: Bad Magic
In October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crimea regions. Although the initial vector of compromise is unclear, the details of the next stage imply the use of spear phishing or similar methods. The victims navigated to a URL pointing to a ZIP archive hosted on a malicious web server.
Executive Summary
RedStinger (also known as Bad Magic) is a moderately sophisticated cyber threat actor targeting government, agriculture, and transportation sectors in Eastern Europe, particularly in conflict-affected regions like Donetsk, Lugansk, and Crimea. The group likely operates with state-sponsored or politically motivated objectives, using spear-phishing campaigns to compromise critical infrastructure organizations.
Goals & Targeting
RedStinger likely operates with strategic objectives aligned with political or military interests, targeting regions and industries that could influence or disrupt national security. The focus on Ukraine-related regions suggests potential ties to Russian-speaking actors or state-sponsored campaigns aiming to destabilize or gather intelligence from critical infrastructure. Key targets include government agencies, which may be sought for diplomatic or strategic reasons, alongside agriculture and transportation sectors, which are essential for economic and operational stability.
Enhanced Description
RedStinger was identified by Kaspersky in October 2022 as an active threat actor targeting government, agriculture, and transportation sectors in Eastern Europe. Initial reports indicate infections in Donetsk, Lugansk, and Crimea regions, suggesting a geographic focus on conflict-affected areas. The attack vector appears to involve spear-phishing or similar methods, with victims directed to URLs hosting malicious ZIP archives. While the exact infrastructure and tools used are not fully detailed, the targeting of critical sectors suggests a mature actor with potential state-sponsored backing. RedStinger's activities align with broader trends of cyber-espionage and disruptive attacks in geopolitical hotspots.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RedStinger's campaign in late 2022 highlights a focus on Eastern European targets, likely leveraging geopolitical tensions. The use of spear-phishing and malicious ZIP files suggests a reliance on common but effective tactics for initial access. The group's activity appears to be limited in timeframe and geographic scope so far, but their targeting of critical sectors indicates potential long-term goals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in full characterization of RedStinger due to limited publicly available details. Further analysis is required to confirm specific tools, tactics, and long-term objectives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics