Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

Russian-origin threat actors have targeted Ukrainian organizations in an effort to steal confidential information and keep ongoing access to compromised networks.

According to a recent assessment from the Symantec and Carbon Black Threat Hunter Team, the activity targeted a local government organization in the nation for a week and a large commercial services organization for two months.

In order to minimize digital footprints and remain undiscovered for extended periods of time, the attackers mostly used dual-use tools and living-off-the-land (LotL) strategies, in conjunction with limited malware.

The cybersecurity teams controlled by Broadcom said in a study published with The Hacker News that the attackers obtained access to the business services organization by installing web shells on servers that were visible to the public, most likely by taking advantage of one or more unpatched vulnerabilities.

One of the attack’s web shells was Localolive, which Microsoft has previously identified as being used by a subset of the Sandworm crew with ties read more about Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *