Russian intelligence has tasked the SolarWinds supply-chain actor with a fresh espionage drive aimed at NATO diplomats and foreign ministries. The operation uses embassy-themed spear-phishing with HTML-smuggling and a multi-stage malware chain, while separate Russian-linked denial-of-service activity has hit Canadian infrastructure. Poland's Military Counterintelligence Service and CERT.PL warned of the campaign in an alert on April 13 that included indicators of compromise. The actor is tracked as Nobelium by Microsoft and as APT29 by Mandiant, the same group behind the SolarWinds supply chain attack nearly three years ago.

How the attack works

According to the Polish alert, the effort is directed at diplomatic personnel from NATO-member states, plus targets in the European Union and Africa. The intended victims are described as foreign ministries and diplomats, specifically the diplomatic corps of countries supportive of Ukraine. Polish authorities also urged vigilance by governments, international organizations, and non-governmental organizations (NGOs).

Each intrusion starts with a tailored spear-phishing message. The emails pretended to be from embassies of European countries and were addressed to selected personnel at diplomatic posts. They offered an invitation to a meeting or collaboration on documents.

Recipients were instructed to follow a link or obtain a PDF in order to view an ambassador's calendar or retrieve meeting details. Both lures led to a hostile website hosting what Polish investigators called the group's signature script, Envyscout.

The site relied on HTML-smuggling to deliver its payload. In that approach, an attacker embeds a malicious file in page content, decodes it with JavaScript at view time, and saves it to the victim device, which complicates server-side detection. The site then displayed a reassurance that the correct file had been downloaded.

Polish investigators said one lure impersonated the Polish embassy. During the observed activity, Envyscout was revised three times to improve obfuscation.

Post-compromise toolset

After initial access, the actor deployed modified variants of the Snowyamber downloader, plus two related implants. Halfrig executes Cobalt Strike as embedded code, while Quarterrig shares code with Halfrig.

Patrick Harr, CEO of SlashNext, noted that well-crafted pretexts using personal details and a trusted sender identity drive spear-phishing success, and assessed that this operation met those conditions. He also described a broader trend toward multi-stage campaigns in which attackers measure what bypasses controls and adjust later waves, including use of automation and machine learning.

The Military Counterintelligence Service and CERT.PL urged any organization that could fall in the actor's area of interest to apply configuration changes to break the delivery mechanism described in the alert.

Russian-linked activity against Canada

Separately, Canadian Prime Minister Justin Trudeau publicly addressed recent Russian-linked cyberattacks on Canadian infrastructure tied to Canada's support of Ukraine. The targets included Hydro-Québec, electric utility, the website for Trudeau's office, the Port of Québec, and Laurentian Bank. The incidents were denial-of-service attacks that took government websites offline for a few hours.

Trudeau said the short outages would not change Canada's position of doing whatever it takes for as long as it takes to support Ukraine. Sami Khoury, head of the Canadian Centre for Cyber Security, said at a news conference last week that no damage was done to Canada's infrastructure but that the threat is real. Khoury advised operators of critical systems, Internet access, health care, and other essential services to protect systems, monitor networks, and apply mitigations.

Mike Parkin with Vulcan Cyber said the activity was unsurprising as Russia's invasion of Ukraine continued into its second year, noting that Russian and pro-Russian actors had remained active against Western targets and that defenders should keep defenses current and correctly configured.

Technical background

This section describes the general technique class, not specifics of this incident.

HTML-smuggling is a delivery and evasion method in which the malicious bytes do not appear as a direct download on the server. Instead, benign-looking HTML and JavaScript reconstruct the payload inside the browser.

A generic illustration of the client-side pattern is:


<a id="doc" download="meeting.pdf">View calendar</a>
<script>
  const blobData = Uint8Array.from(atob(encodedPayload), c => c.charCodeAt(0));
  const blob = new Blob([blobData], {type: 'application/octet-stream'});
  document.getElementById('doc').href = URL.createObjectURL(blob);
</script>

Defenders can disrupt this class of delivery with generic hardening such as blocking untrusted script-created blobs, restricting unsigned macros and script execution, logging browser file-creation events, and inspecting proxy logs for embassy-themed lures that lead to newly created download pages.