{"id":3188,"date":"2026-05-06T12:07:00","date_gmt":"2026-05-06T10:07:00","guid":{"rendered":"https:\/\/lab52.io\/blog\/?p=3188"},"modified":"2026-05-06T12:08:08","modified_gmt":"2026-05-06T10:08:08","slug":"easterbunny","status":"publish","type":"post","link":"https:\/\/lab52.io\/blog\/easterbunny\/","title":{"rendered":"EasterBunny: advanced espionage artifacts attributed to APT29"},"content":{"rendered":"\n<p>During 2019, as part of the results of S2 Grupo\u2019s incident management service, LAB52 gained access to a set of artifacts\u2014and a large amount of evidence collected during the incident\u2014which made it possible to conduct an exhaustive investigation linking the highly sophisticated campaign to APT29.<\/p>\n\n\n\n<p>Starting in November 2025, the information about these artifacts was finally declassified, and the results were compiled into a detailed report that can be downloaded below.<\/p>\n\n\n\n<p>Even today, the campaign still provides very interesting insights into malware deployment in targeted attacks, which we hope will contribute to the community. <\/p>\n\n\n\n<p>Download the full report from <a href=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2026\/05\/LAB52EasterBunny.pdf\">here<\/a>.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Intelligence Availability Notice<\/h1>\n\n\n\n<p>This article presents selected insights derived from our broader threat intelligence operations and coverage. Additional details related to this campaign, as well as other investigations and ongoing intelligence activities, are enriched and available through our private intelligence feed.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>During 2019, as part of the results of S2 Grupo\u2019s incident management service, LAB52 gained access to a set of artifacts\u2014and a large amount of evidence collected during the incident\u2014which made it possible to conduct an exhaustive investigation linking the highly sophisticated campaign to APT29. Starting in November 2025, the information about these artifacts was [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":3192,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[21,1],"tags":[66,90],"class_list":{"0":"post-3188","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-apt","8":"category-uncategorised","9":"tag-apt29","10":"tag-easterbunny","11":"entry"},"featured_image_src":"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2026\/05\/eb1-600x400.jpg","featured_image_src_square":"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2026\/05\/eb1-600x600.jpg","author_info":{"display_name":"Er1c_C","author_link":"https:\/\/lab52.io\/blog\/author\/er1c_c\/"},"_links":{"self":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts\/3188"}],"collection":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/comments?post=3188"}],"version-history":[{"count":5,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts\/3188\/revisions"}],"predecessor-version":[{"id":3200,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts\/3188\/revisions\/3200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/media\/3192"}],"wp:attachment":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/media?parent=3188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/categories?post=3188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/tags?post=3188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}