APTMembers
APT

APT29 Deploys Four-Layer Browser Fingerprinting in Energy-Sector Spearphish

A spearphishing operation targeting energy-sector organisations uses keyed per-victim URLs, real-time User-Agent Client Hints profiling, randomized deep-path routing, and pixel beacon telemetry — four independent evasion mechanisms operating in concert before any payload reaches an endpoint. CTX Team attributes the two-domain cluster to APT29 with medium confidence, citing espionage motivation and tightly bound shared infrastructure activated after a deliberate four-month dormancy period.

Jun 3, 2026, 12:23 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamActorAPT29MinidionisIOC18MITRE4

A spearphishing operation targeting energy-sector organisations has surfaced carrying an unusually disciplined anti-analysis architecture: two purpose-built domains deploying keyed URL access control, real-time browser fingerprinting via User-Agent Client Hints, per-victim randomized path generation, and a delivery-confirmation pixel beacon — four independent mechanisms operating in concert to profile victims, gate payload access, and frustrate automated detection, all before a single…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence