The hacker group abused Yandex.Direct, an online advertising network to post the malvertising campaign and the malware hosted on GitHub. ESET researchers observed the campaigns started in late October 2018 and is still active. The campaign primarily targeted corporate accounting departments, where attackers lure the targets searching for keywords download invoice template, contract example or contract form and to compromise their computers. They have signed the malicious files with multiple code-signing certificates to show users that they are installing the genuine product and not the tampered one.”]

