PwC reported an ongoing attribution effort into a threat actor that allegedly trojanized OpenHardwareMonitor and used the backdoored software to target a poorly covered geographic region. Investigators said they had not established firm ties to any publicly known state-linked or named APT group, but documented a broad intrusion set that included PowerShell, Visual Basic, cmd.exe, BITS jobs, XSL script processing, template injection, host and network discovery, and data theft over the command-and-control channel. The report also published indicators of compromise including file hashes, domains, IP infrastructure, and a ProtonMail address linked to the activity.
The campaign’s use of Visual Basic aligns with a long-established tradecraft pattern tracked in MITRE ATT&CK as T1059.005, which covers execution through VBA, VBScript, and related Visual Basic interpreters. MITRE documents show the technique has been repeatedly used by espionage actors, ransomware operators, and destructive threat groups for payload delivery, persistence, reconnaissance, and command execution, including in operations attributed to Sandworm, Lazarus, and APT29. In this case, the Visual Basic component appears as one element of a wider toolset supporting execution, discovery, and exfiltration in the suspected supply-chain-style intrusion.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
The PwC blog states it complements a talk presented at the SANS CTI Summit on 27 January 2021. That presentation concerned the threat activity later discussed as the in-Tur-est actor, including the backdoored OpenHardwareMonitor targeting.
During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. This reflects continued operational use of Visual Basic-based scripting in the follow-on power grid intrusion.
During the 2015 Ukraine Electric Power Attack, Sandworm Team used a VBA script called vba_macro.exe. The macro dropped FONTCACHE.DAT, identified as the primary BlackEnergy implant, along with rundll32.exe, NTUSER.log, and desktop.ini.
PwC reported that attribution for the in-Tur-est threat actor remained in the technical clustering phase of its 4C model, with no clear links to any well-known government- or organization-attributed APT group. The report also disclosed ATT&CK mappings and indicators of compromise including hashes, domains, IP addresses, and a ProtonMail address tied to the activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.