started · updated
Arctic Wolf detects spear-phishing campaign targeting European infrastructure
Arctic Wolf Labs has uncovered a spear-phishing campaign targeting healthcare organizations, industrial manufacturing, and critical infrastructure across Central and Eastern Europe. The attackers utilized procurement-themed lures, impersonating various companies and specifically posing as ‘Baltic Control’ in three different countries. The campaign utilized a single template that was deployed across five countries.
The technical attack begins with a malicious Excel attachment. Once opened, it triggers a multi-stage infection chain involving an HTML Application (HTA) payload, PowerShell, and highly obfuscated JScript. This process eventually deploys a LuaJIT interpreter and a disguised Lua script.
A key component of the attack is the use of DonutLoader, a known memory injector, to load an infostealer into a running process. The malware establishes a command-and-control connection to collect system information, browser-stored credentials, cryptocurrency wallet data, and Discord artifacts. The stolen data is then prepared and exfiltrated in individual data blocks.