Ukraines main cybersecurity incident response team released a list on Friday of the five most persistent hacking groups and malware families attacking Ukraines critical infrastructure.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the country has recorded 802 cyberattacks since Russia invaded the country earlier this year. That compares to just 362 documented attacks during the same time last year, CERT-UA said. Here are the groups and malware behind some of the biggest attacks:
Who: A threat actor notorious for targeting Ukraine since 2014 and backed by the Russian Federal Security Service (FSB). Prior to 2022, the Security Service of Ukraine attributed around 5,000 cyberattacks to Armageddon and were able to identify five members of the group and trace the malware to Russian hacking platforms. The group has used a number of tactics over the years including Outlook macros, EvilGnome backdoor, planted malware, and exposed vulnerabilities. Despite Ukrainian efforts to thwart the group over the years, Armageddon has remained aggressive.
What: In April, CERT-UA attributed a number of phishing emails to Armageddon which were sent to Ukrainian organizations and other European government agencies. The emails lured recipients by using the subject line, Information on war criminals of the Russian Federation, which provided a downloadable file. When the file was opened, a PowerShell script would run and infect the device.
In March a similar phishing email was sent to Latvian government officials with a file containing war information which allowed the malware to download. Most recently, on April 20, the group was linked to new variants of the Backdoor.Pterodo malware payload. Armageddon has used this payload in the past, however, by constantly creating new variants they are able to quickly shift to a new one after the previous one is detected and blocked. Although their tactics are not the most complex, their ability to remain persistent in efforts against Ukraine has made them a notable threat.
Who: According to research published by Mandiant, UNC1151 is a Belarus-aligned hacking group who has been active since 2016. The group has previously targeted government agencies and private organizations in Ukraine, Lithuania, Latvia, Poland, and Germany also attacking Belarusian dissidents and journalists. Historically, UNC1151 has stolen victim credentials through registered credential theft domains that spoof legitimate websites. UNC1151 has also been linked to the Ghostwriter campaign based on research that suggests UNC1151 provided them with technical support and findings that show similarities in their narratives. Due to the fact that the group has never targeted Russia and based on the relationship between Belarus and Russia, UNC1151 has been tied to Russian operations.
What: Since Russia invaded Ukraine the group has remained aggressive through a variety of attacks. In January the group was linked to the defacement of multiple Ukrainian government websites which displayed a message claiming that personal data was made public. On February 25, CERT-UA warned the public of spearphishing campaigns targeting the email and facebook accounts of Ukrainian military personnel. The group was able to gain access to messages and were able to use the contacts of the accounts to send out more emails. On March 7, CERT-UA found the state organizations of Ukraine had devices infected with MicroBackdoor a malicious program executed by UNC1151.
Who: APT28 (also referred to as Fancy Bear) is backed by Russias military intelligence service (GRU). According to Mandiant research, the group has conducted cyberespionage operations that align with the interests of the Russian government since 2007, however, the government ties were not confirmed until December, 2016 after an analysis by the Department of Homeland Security (DHS) and the FBI. ATP28 has been involved in a number of cyberattacks in which they have stolen highly sensitive information including; the conflict in Syria, NATO-Ukraine relations, the European Union refugee and migrant crisis, the 2016 Olympics and Paralympics Russian athlete doping scandal, public accusations regarding Russian state-sponsored hacking, and the 2016 U.S. presidential election, according to a report by Mandiant.
What: ATP28 was linked to the cyberattack on US satellite communications provider Viasat. The attackers gained access to Viasats KA-SAT network in Ukraine on February 24, leaving many Ukrainians without internet access. Although ATP28s involvement in the attack has not been confirmed, SentinelOne has alluded to their involvement based on the similarities between the AcidRain malware used in the Viasat attack and a VPNFilter malware used in the 2018 disruption of hundreds of thousands of routers which the FBI confirmed. On April 6, Microsoft obtained a court order granting the company permission to take control of seven domains used by APT28 to conduct their attacks.
Who: Russian hacktivists and threat actors everywhere have been using the AgentTesla and XLoader malwares for some time, according to Check Point Research. AgentTesla has been around since 2014, according to security firm TitanHQ, and is used as a program to steal passwords. It has grown in popularity as customers can pay subscription fees ranging from $15 to $69. XLoader is another malware that was rebranded in 2020 from the previous name, Formbook. XLoader targets Windows and Mac devices through phishing emails and can collect passwords and screenshots, log keystrokes, and plant malicious files for a fee of $49 on the dark web.
What: On March 9, CERT-UA released findings showing a mass-distributed malicious email thread that used the topic line, letter of approval of cash security, which was sent to a variety of Ukrainian state organizations. The email contained a file attachment which downloaded and ran the XLoader malware. Once infected, authentication data from the device was collected and sent back to the hackers. Other phishing campaigns have been linked to AgentTesla including emails sent to Ukrainian citizens containing files with the IcedID malware which operates as a banking trojan to steal credentials.
Who: Russian hacktivists and cyber spies use GrimPlant and GraphSteel which function as downloaders and droppers and fall under the umbrella term Elephant Framework tools that are written in the same language and are used to target government organizations through phishing attacks. Threat analysis firm, Intezer, details this framework and provides an in-depth analysis of the malwares. GrimPlant is not overly sophisticated and grants attackers remote control of PowerShell commands, while GraphSteel is used to exfiltrate sensitive data.
What: On March 11, CERT-UA revealed that coordinating entities had received emails regarding instructions to increase security protocol. The email contained a link which provided a critical updates download through a 60MB file. After further investigation, they found that the file prompted a chain of other downloads including the GrimPlant and GraphSteel backdoors. Hackers were then able to steal sensitive information.
On March 28, CERT-UA disclosed another phishing campaign that planted GrimPlant and GraphSteel on the devices of government officials using the subject Wage arrears. The attached document contained accurate information, however, the file also downloaded a program that ran both GrimPlant and GraphSteel. CERT-UA released a statement earlier this month alerting the public of the latest phishing email which downloaded GrimPlant and GraphSteel through an attachment labeled, Aid request COVID-19-04_5_22.xls.
Emma Vail is an editorial intern for The Record. She is currently studying anthropology and women, gender, and sexuality at Northeastern University. After creating her own blog in 2018, she decided to pursue journalism and further her experience by joining the team.
View original post here:
A deeper look at hacking groups and malware targeting Ukraine - The Record by Recorded Future
- The cartoon that sums up the world's 'migrant crisis ... [Last Updated On: May 9th, 2018] [Originally Added On: May 9th, 2018]
- Migrant crisis: EU leaders split over new migrant deal ... [Last Updated On: July 5th, 2018] [Originally Added On: July 5th, 2018]
- Blame for the migrant crisis lies with national ... [Last Updated On: July 5th, 2018] [Originally Added On: July 5th, 2018]
- Migrant crisis: EU leaders plan secure migrant centres ... [Last Updated On: July 5th, 2018] [Originally Added On: July 5th, 2018]
- How Strive Masiyiwa is trying to stem the migrant crisis ... [Last Updated On: July 9th, 2018] [Originally Added On: July 9th, 2018]
- Europe's Refugee and Migrant Crisis - Sputnik International [Last Updated On: November 27th, 2018] [Originally Added On: November 27th, 2018]
- The migrant crisis - The Truthseeker [Last Updated On: December 14th, 2018] [Originally Added On: December 14th, 2018]
- Migrant crisis - Migrant crisis - Pictures - CBS News [Last Updated On: December 15th, 2018] [Originally Added On: December 15th, 2018]
- U.S. Decision To Cut Central America Aid Could Worsen ... [Last Updated On: April 9th, 2019] [Originally Added On: April 9th, 2019]
- Europe's Migrant Crisis | Reuters.com [Last Updated On: April 20th, 2019] [Originally Added On: April 20th, 2019]
- True Christianity: Imperfect People Striving Toward Perfection [Last Updated On: May 2nd, 2019] [Originally Added On: May 2nd, 2019]
- Europe: Looking for a Savior? - Life, Hope & Truth [Last Updated On: May 2nd, 2019] [Originally Added On: May 2nd, 2019]
- Does God Exist? Proof 1: Origin of the Universe - Life ... [Last Updated On: May 2nd, 2019] [Originally Added On: May 2nd, 2019]
- The Migrant Crisis: What Does It Mean? - Life, Hope & Truth [Last Updated On: May 2nd, 2019] [Originally Added On: May 2nd, 2019]
- alizyme Drugs & Medications for ailments [Last Updated On: June 5th, 2019] [Originally Added On: June 5th, 2019]
- Medicinal plants, herbs and mushrooms - Basement Shaman [Last Updated On: June 5th, 2019] [Originally Added On: June 5th, 2019]
- Trump administration announces the end of 'catch and release' - AZCentral [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- What is the real story behind Judaism in Hungary? - JNS.org [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Fewer asylum seekers arriving in Finland | Yle Uutiset - YLE News [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Franciscan sister says respect for migrants under threat - Catholic San Francisco [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- UK officials tell migrants in France: You are being lied to by people smugglers - Sky News [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Germany looks to Mexico to help tackle nursing-care crisis - DW (English) [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- The End of Asylum? - Foreign Policy In Focus [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Stop Blaming Immigrants for Right-Wing Extremism - Just Security [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- US, El Salvador Sign Asylum Deal - DTN The Progressive Farmer [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- US not facing deep crisis in own neighbourhood: Central Americans denied asylum and aid - Norwegian Refugee Council [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Number of migrants now growing faster than world population, new UN figures show - UN News [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- France's Macron Toughens Immigration Stance Amid Fears of More Asylum Seekers - VOA News [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Migrants in Limbo - Commonweal [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Climate Migrants May Number 143 Million by 2050 - The Daily Beast [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Leading aid agency calls for urgent EU action to tackle the migration and asylum crisis - The Parliament Magazine [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- 5 EU Countries Agree on Distribution of Migrants - VOA News [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- No end in sight: Mass exodus of Venezuelan refugees flood into neighboring countries - Big Think [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- EU ministers meet in Malta to discuss migrant crisis - Times of Malta [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Trump Admin Ignored Its Own Data Linking Migrant Crisis to Climate Change - EcoWatch [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Mitsotakis Want's Help With Greece's Refugee, Migrant Crisis - The National Herald [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- A dangerous red flower is driving record numbers of migrants to flee Guatemala - USA TODAY [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Interior ministers demand EU response to new migrant crisis - Vatican News [Last Updated On: September 24th, 2019] [Originally Added On: September 24th, 2019]
- Man arrested in northern Lincolnshire suspected of trying to smuggle migrants across Channel - Grimsby Live [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- No refugees need apply - The Boston Globe [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- This new tour of Berlin is guided by a Syrian refugee - Lonely Planet Travel News [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- DHS Chief Urges Congress to Address the Fundamental Drivers of Migrant Crisis: Funds Will Only Mitigate It - Independent Journal Review [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Undocumented Poets and Writers Are Vital to the Struggle for Migrant Justice - The Nation [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Pope unveils migrant sculpture in St Peters Square and bemoans worlds indifference to their plight - The Independent [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- French police turn blind eye and wave 'bye bye' to migrants making boat trips to UK - Express [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- EU migrant crisis: France cannot take in all the misery in the world says Macron - Express.co.uk [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- French police to double beach patrols after discovering two dead Iraqi migrants suspected of attempting to get to Britain - The Telegraph [Last Updated On: October 16th, 2019] [Originally Added On: October 16th, 2019]
- Winter poses new threat to migrants in Bosnian forest camp - The Wider Image [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- The White Houses Build the Wall Game Was Horrible. It Was Also Really Boring. - Yahoo Lifestyle [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- France to set migrant worker quotas in bid to appeal to rightwing voters - The Guardian [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- UN official says fight for women's equality is far from over - Daily Inter Lake [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- There's Still No Plan to Deal With Migrants in the Mediterranean - The Nation [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- Europe has built barriers six times the length of the Berlin Wall since 1989 - Euronews [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- U.S. too focused on 'freezing out asylum seekers' to fix refugee deal with Canada: researcher - CBC.ca [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- Retired Admiral Says Turkey Pushing Refugee, Migrant Crisis on Greece - The National Herald [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- Seeds of Europe's 'migrant crisis' are in Europe - Mail and Guardian [Last Updated On: November 6th, 2019] [Originally Added On: November 6th, 2019]
- How Lost Children Archive estranges the idea of aliens - The Guardian [Last Updated On: December 21st, 2019] [Originally Added On: December 21st, 2019]
- Terrified boy found wandering alone on M6 is migrant who doesnt know where his parents are - The Sun [Last Updated On: December 21st, 2019] [Originally Added On: December 21st, 2019]
- Church can't keep up with rising refugee numbers, Archbishop says - Loop News Trinidad and Tobago [Last Updated On: December 21st, 2019] [Originally Added On: December 21st, 2019]
- At least three migrant boats intercepted trying to cross Channel in horrific conditions - Express [Last Updated On: December 21st, 2019] [Originally Added On: December 21st, 2019]
- Costa Rica will ask for international help to assist migrant crisis - The Tico Times [Last Updated On: December 21st, 2019] [Originally Added On: December 21st, 2019]
- Officials have been cleared of wrongdoing in the deaths of 2 migrant kids last year, an internal watchdog says - Business Insider [Last Updated On: December 21st, 2019] [Originally Added On: December 21st, 2019]
- Riots in overcrowded Greek migrant camp on Samos - InfoMigrants [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- The biggest news from Italy in 2019 Italianmedia - Il Globo [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- Top 10 Films of 2019 - Boca Raton [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- Pope Francis decries Libyan migrant camps as places of torture and slavery - The National [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- Triumph of the right in Sweden is a result of the total failure of liberalism - RT [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- A crisis within a crisis: Hundreds of unaccompanied minors left to 'fend for themselves' on Lesbos - InfoMigrants [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- Repeat of 2015 migrant crisis inevitable without action: Turkish president | TheHill - The Hill [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- WDET's Top Story, News and Issue of 2019 - WDET [Last Updated On: December 24th, 2019] [Originally Added On: December 24th, 2019]
- The 2010s have been the best decade for European populism to date - Daily Gaming Worlld [Last Updated On: January 5th, 2020] [Originally Added On: January 5th, 2020]
- Turkey's gambit in Libya could tear the country apart - The National [Last Updated On: January 5th, 2020] [Originally Added On: January 5th, 2020]
- The refugee crisis showed Europes worst side to the world - The Guardian [Last Updated On: January 5th, 2020] [Originally Added On: January 5th, 2020]
- Columnist Razvan Sibii: The resistance, as organized by immigration lawyers - GazetteNET [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]
- What does Austria's new governing coalition mean for migrants? - InfoMigrants [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]
- In a lifetime on the border, Agent Chancy Arnold has seen it transform - Los Angeles Times [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]
- From Nazi camps to the Lake District: the story of the Windermere children - The Guardian [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]
- 10 stories that changed Europe in the last decade - Euronews [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]
- No network in times of crisis - The Hindu [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]
- Muslim population of England smashes three million mark for first time ever, figures reveal - The Sun [Last Updated On: January 6th, 2020] [Originally Added On: January 6th, 2020]