Researchers linked multiple highly targeted phishing campaigns to Fighting Ursa / APT28 and related tracking names including ITG05, Fancy Bear, and Forest Blizzard, using tailored geopolitical and diplomatic lures to deliver the HeadLace backdoor. In one operation, attackers sent a fake "Diplomatic Car For Sale" advertisement for an Audi Q7 to likely diplomatic targets, leading victims to a ZIP archive containing a double-extension executable disguised as an image. The malware chain abused legitimate services such as Webhook.site and ImgBB, sideloaded a malicious WindowsCodecs.dll through a legitimate calc.exe, and used a batch script to launch Microsoft Edge with Base64-encoded content to fetch and run a second-stage payload.
A separate campaign used authentic-looking documents themed around the Israel-Hamas conflict to target academic, finance, diplomatic, and policy-linked organizations involved in humanitarian aid and foreign-policy decision-making, primarily in Europe. IBM said the infrastructure applied country-based filtering so only intended victims in specific countries could retrieve the malware, with targets identified across at least 13 countries, including several UN Human Rights Council members. Across the reporting, HeadLace was described as closely associated with this actor set, reinforcing assessments that the activity supported selective intelligence collection against diplomatic and policy-focused entities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Webhook.site URL used in the Fighting Ursa phishing chain was submitted to VirusTotal on March 14, 2024. Unit 42 identified this URL as part of the infrastructure serving the fake diplomatic car sale lure and malware delivery flow.
Beginning as early as March 2024, Fighting Ursa ran a phishing campaign likely targeting diplomats with a fake 'Diplomatic Car For Sale' advertisement for an Audi Q7 Quattro SUV. The infection chain abused Webhook.site and ImgBB and ultimately deployed the HeadLace backdoor on Windows systems.
As of December 2023, IBM X-Force uncovered a highly targeted campaign using authentic lure documents themed around the Israel–Hamas war to deliver the ITG05-exclusive HeadLace backdoor. The operation appeared aimed at entities influencing humanitarian aid allocation, primarily in Europe, with targets identified across at least 13 countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityintelligence.com
Open sourceunit42.paloaltonetworks.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.