<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article NOBELIUM: A Playbook for Handling a Wide-Scale Spear Phishing Campaign in Cortex XSOAR Articles</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/nobelium-a-playbook-for-handling-a-wide-scale-spear-phishing/ta-p/410075</link>
    <description>&lt;P&gt;&lt;SPAN&gt;On May 27, 2021, &lt;/SPAN&gt;&lt;A href="https://blogs.microsoft.com/on-the-issues/2021/05/27/nobelium-cyberattack-nativezone-solarwinds/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Microsoft&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; reported a wide-scale spear phishing campaign attributed to APT29, the same threat actor responsible for the &lt;/SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/blog/security-operations/cortex-xsoar-solarstorm-sunburst/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;SolarWinds campaign, SolarStorm&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. This attack had a wide range of targets for an APT spear phishing campaign—about 3,000 email accounts targeted within 150 organizations.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;We can help!&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;On May 28th, Cortex XSOAR’s security research team released &lt;/SPAN&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/playbooks/NOBELIUM---wide-scale-APT29-spear-phishing" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;NOBELIUM&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;, a wide-scale APT29 spear-phishing playbook for hunting and responding to the attack. &lt;/SPAN&gt;&lt;STRONG&gt;NOBELIUM - Wide Scale APT29 Spear-Phishing &lt;/STRONG&gt;&lt;SPAN&gt;is part of the&lt;/SPAN&gt; &lt;STRONG&gt;&lt;A href="https://xsoar.pan.dev/marketplace/details/MajorBreachesInvestigationandResponse" target="_blank" rel="noopener"&gt;Rapid Breach Response&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;content pack available for download from the &lt;A href="https://www.paloaltonetworks.com/cortex/xsoar/marketplace" target="_self"&gt;Cortex XSOAR Marketplace&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Rapid Breach Response is a collection of playbooks developed by our security research teams in response to high-profile breaches and attacks, such as SolarStorm.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Learn more here: &lt;A href="https://www.paloaltonetworks.com/blog/2021/06/cortex-xsoar-nobelium-spear-phishing/" target="_self"&gt;Cortex XSOAR for Nobelium Spear Phishing Attacks Rapid Response&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mbordach10_1-1622382232719.png" style="width: 668px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34145iE28A092F40D471E1/image-dimensions/668x388/is-moderation-mode/true?v=v2" width="668" height="388" role="button" title="mbordach10_1-1622382232719.png" alt="mbordach10_1-1622382232719.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2025 18:54:01 GMT</pubDate>
    <dc:creator>mbordach10</dc:creator>
    <dc:date>2025-04-10T18:54:01Z</dc:date>
    <item>
      <title>NOBELIUM: A Playbook for Handling a Wide-Scale Spear Phishing Campaign</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/nobelium-a-playbook-for-handling-a-wide-scale-spear-phishing/ta-p/410075</link>
      <description>&lt;P&gt;&lt;SPAN&gt;NOBELIUM is a playbook for handing a&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;wide-scale spear phishing campaign, such as the one Microsoft experienced in late May 2021.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 18:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/nobelium-a-playbook-for-handling-a-wide-scale-spear-phishing/ta-p/410075</guid>
      <dc:creator>mbordach10</dc:creator>
      <dc:date>2025-04-10T18:54:01Z</dc:date>
    </item>
  </channel>
</rss>

