Sophos highlighted a Secureworks incident response case in which the Russia-linked IRON LIBERTY espionage group likely intercepted a victim’s web traffic and used a man-on-the-side technique to deliver Karagany malware. In the 2018 intrusion, the victim downloaded an Adobe Flash installer over unencrypted HTTP from adobe.com; within seconds, Karagany was written to disk, installed as SearchIndexer.exe, and configured to persist through the user’s Startup folder. The installer then appeared to self-modify, leaving behind a legitimate Adobe Flash binary to reduce suspicion.
Investigators assessed that a compromise of Adobe, an internal man-in-the-middle attack, and BGP hijacking were unlikely, concluding that interception through a compromised router outside the victim network was the most plausible explanation. The case underscores how attackers can gain initial access by manipulating Internet traffic rather than directly breaching endpoints, and it reinforces broader warnings that espionage actors are increasingly targeting routers, service providers, and other supply-chain pathways to undermine trust in core Internet infrastructure.
TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
After ruling out compromise of Adobe, an internal man-in-the-middle attack, and BGP hijacking as likely explanations, Secureworks concluded that interception of traffic via a compromised router outside the victim network was the most plausible scenario. The assessment highlighted how attackers can exploit core Internet infrastructure and trusted software delivery paths for initial access.
In a 2018 incident response case, forensic evidence indicated that the Russia-linked IRON LIBERTY espionage group likely used a man-on-the-side attack to deliver Karagany malware through a trojanized Adobe Flash installer downloaded over HTTP from adobe.com. The malware was written to disk within seconds, installed as SearchIndexer.exe, persisted via the user's Startup folder, and the installer appeared to leave behind a legitimate Adobe Flash binary.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.