Threat Analysis Group

Government-backed actors exploiting WinRAR vulnerability



a picture of code
a picture of code
a box showing lines of code

“Training of drone operators” decoy document from FROZENBARENTS campaign

a decoy document with letters

FROZENLAKE decoy document impersonating a Ukrainian public policy think tank

a decoy document from the Frozenlake campaign
box showing code

Decoy PDF used in ISLANDDREAMS campaign

decoy PDF reading "password required"
black box showing lines of code