
Félix AIME
Principal Threat Researcher
Articles by Félix AIME

APT28 leverages multiple phishing techniques to target Ukrainian civil society
The APT28 intrusion set (aka. Sofacy, PawnStorm, Fancy Bear), associated to the Russian GRU was observed using multiple phishing techniques to target the Ukrainian civil society.

Sekoia analysis of the #VulkanFiles leak
In January 2023, French newspaper Le Monde offered Sekoia to cooperate on investigating exfiltrated Russian-written documents related to the Moscow-based private company Vulkan.

Peeking at Reaper’s surveillance operations
In this blogpost you will find the results of a survey conducted by our analysts on two Command and Control servers (C2s) of the North Korea-nexus intrusion set Reaper (aka APT37). This investigation led to the uncovering of several phishing webpages

Calisto shows interest in entities involved in Ukraine war support
Calisto (aka Callisto, COLDRIVER) is suspected to be a Russian-nexus intrusion set active since at least April 2017. Although it was not publicly attributed to any Russian intelligence service, past Calisto operations showed objectives and victimology that were closely aligned with Russian strategic interests.






