CSIDB logo
Incident

Baranovichi Operational Management of the Armed Forces

Incident posture

Attack window
Jun 2017
Location
Belarus
Status
Historical
CIA posture
Available to members
Updated
2025-12-01 00:00

Linked entities

Victim
Baranovichi Operational Management of the Armed Forces
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A phishing campaign targeted Belarusian military entities, including the Baranovichi Operational Management, using updated variants of the CMSTAR Trojan. Attackers sent malicious emails with attachments disguised as documents related to the Zapad-2017 joint military exercise. These attachments deployed backdoors named PYLOT and GAMECHANGERY, enabling remote command execution and data exfiltration. The malware employed XOR encryption, registry modifications for persistence, and communicated with command-and-control servers via encrypted channels. Decoy materials mimicked legitimate exercise preparations to deceive recipients. The campaign involved multiple CMSTAR variants with refined obfuscation techniques and leveraged military-themed lures across a three-month operation.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Between June and August 2017, threat actors conducted a phishing campaign targeting Belarusian government entities, including military and diplomatic addresses such as [email protected]. Attackers sent 20 unique emails with subject lines referencing the Zapad-2017 joint military exercise between Russia and Belarus, scheduled for September 14–20, 2017. Emails contained malicious attachments including RTF documents, Microsoft Word files, and a RAR archive containing a decoy document about Zapad-2017 preparations, images, and a .scr executable disguised as a Windows folder. The campaign deployed three variants of the CMSTAR Trojan (CMSTAR.A, CMSTAR.B, and CMSTAR.C), which exhibited minor string obfuscation modifications compared to earlier versions observed in 2015–2016. These variants downloaded two novel backdoor payloads—GAMMY and PYLOT—enabling remote command execution and data exfiltration.

The malware employed XOR encryption and registry modifications for persistence. PYLOT communicated with the command-and-control (C2) domain oeiowidfla22.com via encrypted traffic, while GAMMY used TLS and injected into svcHost.exe or rundll32.exe processes. Decoy documents mimicked legitimate Zapad-2017 exercise materials to enhance credibility. Palo Alto Networks identified the campaign through AutoFocus threat intelligence, noting protections via malicious domain blocking, macro exploit prevention (CVE-2015-1641), and WildFire behavioral analysis. The attackers’ infrastructure and tactics aligned with historicalSTAR operations, though no attribution or victim-side containment measures were disclosed in available reporting.

Sources

Sources available to members: 1 source.

CSIDB