• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ukraine continues to face cyber espionage attacks from russian hackers

Ukraine Continues to Face Cyber Espionage Attacks from Russian Hackers

You are here: Home / General Cyber Security News / Ukraine Continues to Face Cyber Espionage Attacks from Russian Hackers
February 1, 2022

Cybersecurity researchers on Monday explained they uncovered evidence of tried attacks by a Russia-joined hacking operation targeting a Ukrainian entity in July 2021.

Broadcom-owned Symantec, in a new report published Monday, attributed the attacks to an actor tracked as Gamaredon (aka Shuckworm or Armageddon), a cyber-espionage collective regarded to be energetic considering that at minimum 2013.

In November 2021, Ukrainian intelligence companies branded the team as a “specific task” of Russia’s Federal Security Support (FSB), in addition to pointing fingers at it for carrying out more than 5,000 cyberattacks towards general public authorities and critical infrastructure located in the country.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Gamaredon attacks generally originate with phishing e-mails that trick the recipients into installing a custom distant accessibility trojan known as Pterodo. Symantec disclosed that, between July 14, 2021 and August 18, 2021, the actor put in several variants of the backdoor as very well as deployed additional scripts and tools.

Automatic GitHub Backups

“The attack chain started with a malicious doc, very likely despatched by way of a phishing email, which was opened by the consumer of the contaminated machine,” the scientists claimed. The id of the impacted firm was not disclosed.

Toward the finish of July, the adversary leveraged the implant to down load and run an executable file that acted as a dropper for a VNC customer ahead of creating connections with a distant command-and-control server beneath their handle.

“This VNC client appears to be the top payload for this attack,” the researchers pointed out, adding the installation was followed by accessing a range of paperwork ranging from position descriptions to delicate company info on the compromised machine.

Ukraine Calls Out False Flag Operation in Wiper Attacks

The findings arrive amidst a wave of disruptive and harmful attacks levied from Ukrainian entities by alleged Russian state-sponsored actors, resulting in the deployment of a file wiper dubbed WhisperGate, close to the exact same time numerous web-sites belonging to the government have been defaced.

Prevent Data Breaches

Subsequent investigation into the malware has considering that unveiled that the code used in the wiper was re-purposed from a faux ransomware campaign referred to as WhiteBlackCrypt that was aimed at Russian victims in March 2021.

Curiously, the ransomware is regarded to incorporate a trident image — that is element of Ukraine’s coat of arms — in the ransom notice it shows to its victims, leading Ukraine to suspect that this might have been a untrue flag operation intentionally supposed to blame a “fake” pro-Ukrainian group for staging an attack on their individual federal government.

Discovered this short article exciting? Comply with THN on Facebook, Twitter  and LinkedIn to read through a lot more exceptional information we write-up.


Some components of this write-up are sourced from:
thehackernews.com

Previous Post: «reasons why every business is a target of ddos attacks Reasons Why Every Business is a Target of DDoS Attacks
Next Post: CISA Tells Organizations to Patch CVEs Dating Back to 2014 Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Enzo Biochem Hit by Ransomware, 2.5 Million Patients’ Data Compromised
  • US and Korean Agencies Issue Warning on North Korean Cyber-Attacks
  • Malicious PyPI Packages Use Compiled Python Code to Bypass Detection
  • New Botnet Malware ‘Horabot’ Targets Spanish-Speaking Users in Latin America
  • The Importance of Managing Your Data Security Posture
  • Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering
  • Insurers Predict $33bn Bill for Catastrophic “Cyber Event”
  • Chinese Phishing Gang “PostalFurious” Expands Campaign
  • Kaspersky Says it is Being Targeted By Zero-Click Exploits
  • North Korea’s Kimsuky Group Mimics Key Figures in Targeted Cyber Attacks

Copyright © TheCyberSecurity.News, All Rights Reserved.