Kaspersky Lab has unveiled a new cyber espionage campaign that has affected users and organizations in nearly forty countries around the world.

The attack is dubbed SneakyPastes. Analysis indicates that it is orchestrated by the cyber group Gaza, which includes three other teams of attackers — Operation Parliament (known since 2018), Desert Falcons (known since 2015), and MoleRats (active at least since 2012).
In carrying out the cyber espionage campaign, the perpetrators actively employed phishing methods. The criminals utilized sites that allow for the rapid distribution of text files, such as web services Pastebin and GitHub, to secretly implant a remote access Trojan into the victims' systems.
The organizers of the attack used malware to steal various confidential information. Specifically, the Trojan combined, compressed, encrypted, and sent a wide range of documents to the attackers.

Approximately 240 individuals and organizations in 39 countries with political interests in the Middle East were victims of the campaign, including government agencies, political parties, embassies, diplomatic missions, news agencies, educational and medical institutions, banks, contracting organizations, civil activists, and journalists, Kaspersky Lab notes.
Currently, a significant portion of the infrastructure used by the attackers to conduct the attacks has been dismantled.
Source: 3dnews.ru
