0x656 - Teknik - Double Tap Campaign: Russia nexus APT possibly related to APT28

0x656 - Teknik - Double Tap Campaign: Russia nexus APT possibly related to APT28

🎙 PolySécure Podcast 👥 540 📅 November 4, 2025 ⏱ 47 min 👁 26 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

Double TapAPT28CERT-UAYara rulesKazakhstan

Summary

In this technical episode of PolySécure Podcast, hosts Nicolas interviews Maxime Arquillière and Amaury-Jacques Garçon, cyber threat analysts at Sekoia.io. They discuss their investigation into the ‘Double Tap’ campaign, a sophisticated phishing operation likely linked to the Russian APT28 group. The investigation began with a CERT-UA report from July 2024, which led them to create Yara detection rules. In mid-October, one of these rules flagged a malicious Word document on VirusTotal, seemingly from the Kazakh Ministry of Foreign Affairs. This discovery led to the identification of 18 similar documents, about ten of which were previously unknown. The infection chain involves a two-stage macro attack: the first document, when macros are enabled, creates a second malicious document in a temporary directory, hence the name ‘Double Tap’. The malware modifies security settings, establishes persistence, and contacts a C2 server, potentially deploying a Python backdoor called ‘Cherry Spy’. The documents were in Kazakh and related to diplomatic topics, suggesting a geopolitical motive. The analysts highlight the importance of open-source intelligence sharing and the impact of their findings, which led to an inspection of the Kazakh ministry. The episode underscores the complexity of CTI work, combining technical analysis with geopolitical understanding.

197 words

Critical Evaluation

Value of the Information & Strength of the Argument

The podcast provides valuable insights into the practical aspects of cyber threat intelligence, detailing the methodology from initial detection to publication. The argumentation is solid, based on concrete technical evidence and a clear logical progression. The analysts explain their reasoning and the steps taken, which enhances credibility. They also discuss the strategic and geopolitical dimensions, adding depth to the technical analysis. The discussion is well-structured and informative, with no obvious logical fallacies.

Scientific Rigor, Source Quality, Title Accuracy

The podcast demonstrates scientific rigor by referencing specific sources, such as the CERT-UA report, and by describing their own technical analysis. The quality of sources is high, as they rely on primary reports and their own reverse engineering. The title accurately reflects the content, focusing on the ‘Double Tap’ campaign and its possible link to APT28. The discussion is consistent with the title, and the analysts provide a thorough examination of the campaign. No comments were provided for analysis.

166 words

Title / Content Match

The title accurately reflects the content, which focuses on the 'Double Tap' campaign and its possible link to APT28.

Quality & Reliability

8/10

The podcast features two cybersecurity analysts from a reputable French CTI company (Sekoia.io) discussing a detailed investigation. They reference a CERT-UA report and their own technical analysis, demonstrating a rigorous methodology. The discussion is technical and specific, with no obvious misinformation. However, as a podcast, it lacks formal peer review and some claims are based on their own analysis.

Key Moments

Cited Sources

  • CERT-UA report on Double Tap campaign — The initial report that triggered the investigation, published in July 2024.
  • Sekoia.io blog post on Double Tap — The analysts' own publication detailing their findings.

Concurring Sources

  • CERT-UA report — The initial report that aligned with the analysts' findings.

Contribution & Novelties

The podcast provides an in-depth look at a real-world CTI investigation, showcasing the process from initial detection to publication. It highlights the importance of open-source intelligence and the value of sharing findings. The ‘Double Tap’ technique is a novel infection chain that adds to the understanding of APT28’s tactics. The geopolitical analysis of targeting Kazakhstan provides a strategic perspective often missing in technical reports.

Pour aller plus loin :

  • APT28 — Background on the threat actor.
  • YARA rules — Official documentation on YARA.
  • CERT-UA — Official website of the Ukrainian CERT.

91 words

Radar Profile

The radar profile shows high scores across all dimensions, indicating a well-rounded and reliable content. The podcast excels in providing detailed technical information and credible sources, with a strong emphasis on practical methodology.

Reliability 8/10