Tag: Russian Espionage Group

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
News

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A then-unknown vulnerability in Zimbra's webmail software allowed a Russian state-sponsored espionage operation to read Western mailboxes for months. The last ninety days' worth of emails, the organization's whole email directory, the browser password, and the codes stored for two-factor recovery are all targeted by the payload. It only took opening the message to get it going. In addition to research from Palo Alto Networks' Unit 42 and Proofpoint, the NSA, CISA, and partner agencies released a joint advisory on the effort on Thursday. The method is described in the alert as "a view-based exploit that only requires a user to view a malicious email" in a client that is susceptible. It claims that since at least July 2025, the actors have been using Zimbra to target and compromise...
Russian Espionage Group Targets Ukrainian Military with Malware via Telegram
News

Russian Espionage Group Targets Ukrainian Military with Malware via Telegram

Under the Telegram alias Civil Defense, a suspected Russian hybrid espionage and influence operation has been seen distributing a combination of Windows and Android malware to the Ukrainian military. Under the handle UNC5812, Mandiant and Google's Threat Analysis Group (TAG) are monitoring the behavior. The threat group was established on September 10, 2024, and runs the civildefense_com_ua Telegram channel. There are 184 subscribers to the channel as of this writing. Additionally, it has a website registered on April 24, 2024, at civildefense.com[.]ua. In a report published with The Hacker News, Civil Defense asserts that it offers free software applications that allow prospective conscripts to observe and share crowdsourced locations of Ukrainian military recruiters read more abou...