Tag: ukraine

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
News

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Nearly a year after patches for the vulnerability were made available, two cyberattack campaigns with ties to Russia have persisted in using a WinRAR security hole to target Ukrainian organizations. Trend Micro has identified Earth Dahu (also known as Gamaredon) and SHADOW-EARTH-066 (also known as UAC-0226) as the cause of the activity. It involves taking use of CVE-2025-8088, a path traversal vulnerability that enables an attacker to use NTFS Alternate Data Streams (ADS) to write files outside of the extraction directory. In July 2025, WinRAR patched it. The results demonstrate "how unmanaged software keeps an exploited entry point open long after the fix ships," according to an investigation released on Monday by Trend Micro researchers Hiroyuki Kakara and Feike Hacquebord. SHA...
Sandworm hackers use data wipers to disrupt Ukraine’s grain sector
News

Sandworm hackers use data wipers to disrupt Ukraine’s grain sector

Several data-wiping malware families have been used by the Russian state-backed hacker organization Sandworm to target Ukraine's government, school system, and grain industry, which is the nation's primary source of income. According to a research released today by cybersecurity firm ESET, the assaults took place in June and September and are part of Sandworm's (also known as APT44) ongoing disruptive activities in Ukraine. By distorting or erasing files, disk partitions, and master boot records in a way that prevents recovery, a data wiper, as its name suggests, aims to erase a target's digital information. It can have a devastating effect on the target, causing disturbances that are hard to recover from. Wiper virus is only employed in sabotage operations, in contrast to ransom...
Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics
News

Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics

Since 2022, a state-sponsored campaign targeting Western logistics and technology industries has been attributed to Russian cyber threat actors. APT28, also known as BlueDelta, Fancy Bear, or Forest Blizzard, has been identified as the organization behind the activities. It is associated with the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center, Military Unit 26165. According to a joint advisory issued by agencies from Australia, Canada, Czechia, Denmark, Estonia, France, Germany, the Netherlands, Poland, the United Kingdom, and the United States, the campaign targets businesses that coordinate, transport, and deliver foreign aid to Ukraine. According to the bulletin, this cyber espionage campaign aimed at technology businesses and logist...
DarkWatchman, Sheriff Malware Hit Russia and Ukraine with Stealth and Nation-Grade Tactics
News

DarkWatchman, Sheriff Malware Hit Russia and Ukraine with Stealth and Nation-Grade Tactics

A massive phishing campaign aimed at distributing the well-known malware DarkWatchman has targeted Russian businesses. According to Russian cybersecurity firm F6, the attacks target companies in the media, tourism, banking and insurance, manufacturing, retail, energy, telecom, transportation, and biotechnology industries. The activity has been traced by IBM X-Force to attacks targeting customers in the telecom, electronic, and industrial sectors in Lithuania, Estonia, and Russia. It is believed to be the work of a financially motivated gang known as Hive0117. Then, in September 2023, a phishing effort targeting the software security, banking, energy, and transportation sectors based in Russia, Kazakhstan, Latvia, and Estonia once more used the DarkWatchman virus read more about D...
Gamaredon Uses Infected Removable Drives to Breach Western Military Mission in Ukraine
News

Gamaredon Uses Infected Removable Drives to Breach Western Military Mission in Ukraine

Gamaredon (also known as Shuckworm), a threat actor associated with Russia, has been implicated in a cyberattack that targeted a foreign military mission stationed in Ukraine with the intention of delivering an updated version of the well-known malware GammaSteel. According to the Symantec Threat Hunter team, the organization targeted a Western nation's military operation, and on February 26, 2025, the first indications of the malicious activity were found. In a report sent to The Hacker News, the threat intelligence section operated by Broadcom stated that "an infected removable drive appears to have been the initial infection vector used by the attackers." First, a Windows Registry value was created under the UserAssist key, and then "mshta.exe" was launched using "explorer.exe...
UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine
News

UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine

Information-stealing malware is being used in a fresh wave of cyberattacks against Ukrainian institutions, according to the Computer Emergency Response Team of Ukraine (CERT-UA). According to the CIA, the operation targets local self-government organizations, law enforcement organizations, and military formations, especially those situated close to Ukraine's eastern border. The attacks entail sending out phishing emails that contain a Microsoft Excel spreadsheet (XLSM) with macro functionality. When the spreadsheet is opened, two pieces of malware are deployed: a PowerShell script from the GitHub repository PSSW100AVB ("Powershell Scripts With 100% AV Bypass") that opens a reverse shell, and an as-yet-unknown stealer known as GIFTEDCROOK. According to CERT-UA, file names and emai...
FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine
News

FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine

The Federal Security Service (FSB) discreetly installed spyware on an Android tablet belonging to a Russian programmer who was arrested earlier this year on suspicion of giving money to Ukraine. The results are the result of a joint inquiry between the First Department and the Citizen Lab at the University of Toronto. According to the article, the spyware installed on his device gives the operator the ability to track the location of a target device, record keystrokes and phone conversations, and read messages from encrypted messaging apps, among other things. After being placed in administrative prison by Russian authorities for 15 days read more about FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine. Get up to date on the latest cybersecurity n...
OfflRouter Malware Evades Detection in Ukraine for Almost a Decade
News

OfflRouter Malware Evades Detection in Ukraine for Almost a Decade

A malware known as OfflRouter has persisted in infecting certain government networks in Ukraine since 2015. Based on an examination of more than 100 private documents infected with the VBA macro virus and published to the VirusTotal malware scanning portal since 2018, Cisco Talos revealed its conclusions. Since 2022, almost 20 of these documents have been uploaded. VBA code to drop and launch an executable called "ctrlpanel.exe" was found in the papers, according to security researcher Vanja Svajcer. The virus is still causing potentially sensitive papers to be uploaded to document repositories that are open to the public in Ukraine. One remarkable feature of OfflRouter is that it cannot be distributed over email; instead, it must be distributed through other channels, like docum...
Ukraine Arrests Trio for Hijacking Over 100 Million Email and Instagram Accounts
News

Ukraine Arrests Trio for Hijacking Over 100 Million Email and Instagram Accounts

Three people have been detained by the Ukrainian Cyber Police on suspicion of stealing over 100 million Instagram accounts and emails from users worldwide. The suspects, who range in age from 20 to 40, are allegedly members of an organized criminal network that resides across the nation. They could spend up to 15 years behind bars if found guilty. Authorities claimed that the accounts were accessed through the use of brute-force attacks, which use methods of trial and error to guess login credentials. A leader oversaw the group's operations and assigned the hacking assignments to the other participants. The cybercrime organization then used the credentials they had obtained illegally to make money by selling them on dark web forums read more Ukraine Arrests Trio for Hijacking Ove...
Russian Hackers Sandworm Cause Power Outage in Ukraine Amidst Missile Strikes
News

Russian Hackers Sandworm Cause Power Outage in Ukraine Amidst Missile Strikes

Sandworm, a notorious Russian hacker, targeted an electrical substation in Ukraine last year, causing a brief power outage in October 2022. According to Google's Mandiant, the hack was a "multi-event cyber attack" that used a novel technique to impact industrial control systems (ICS). The actor "first used OT-level living-off-the-land (LotL) techniques to likely trip the victim's substation circuit breakers, resulting in an unplanned power outage that coincided with mass missile strikes on critical infrastructure across Ukraine," according to the company. Sandworm then carried out a second disruptive event in the victim's IT environment by deploying read more Russian Hackers Sandworm Cause Power Outage in Ukraine Amidst Missile Strikes. Get up to date on the latest cybersecurity ...