UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉
Вікторія ГорбікThat's Life
18 March 2025, 15:29
2025-03-18
Hackers are using Signal to send phishing links to defense industry employees and representatives of the Defense Forces. What to avoid
CERT-UA warns of a new wave of hacker attacks on the Signal messenger, targeting employees of defense-industrial complex enterprises and representatives of the Defense Forces of Ukraine.
CERT-UA warns of a new wave of hacker attacks on the Signal messenger, targeting employees of defense-industrial complex enterprises and representatives of the Defense Forces of Ukraine.
Attackers sent phishing messages with malicious archives via Signal. The attached files were disguised as meeting reports. Sometimes the messages appeared to come from familiar contacts who had been compromised by hackers.
Typically, the mentioned archives contain a file with the extension «.pdf», as well as an executable file classified as DarkTortilla, which is a cryptor/loader software tool whose purpose is to decrypt and launch (including by injection) the Dark Crystal RAT (DCRAT) remote control software tool.
CERT-UA has noticed similar criminal activity with the identifier UAC-0200. It has been observed since the summer of 2024. This year, starting in February, the decoy messages mostly mention UAVs, electronic warfare equipment, and other military technologies.
72% of cyber incidents have a medium level of criticality. Cyber expert from the Ministry of Defense on attacks on the ministry by Russian hackers: method, countermeasures and bias
Attackers are using the EvilLoader exploit to force Telegram users on Android to install malicious software. What the messenger’s representatives say about this