A colleague received a banking-themed phish a colleague received back in July. The root domain had an open directory leading to other phishes. No personal victim information appeared on the pitch, and elements of its language could be tracked back to at least 2012. The lack of input validation suggests that the threat actor is not sharp enough to steal efficiently. We have a reasonable, evidence-backed suspicion that a Russian actor has instigated a low-sophisticated phishing wave sent to targets.”]
Source: https://blog.malwarebytes.com/101/2016/11/attribution-part-ii-dont-overthink-it/

