Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Russian hackers attacked Ukrainian government institutions via Signal

APT28, a hacking group linked to Russian intelligence, is attacking Ukrainian government institutions. The attackers use a multi-step chain that begins with sending malicious documents via the Signal messenger.

Leave a comment
Russian hackers attacked Ukrainian government institutions via Signal

APT28, a hacking group linked to Russian intelligence, is attacking Ukrainian government institutions. The attackers use a multi-step chain that begins with sending malicious documents via the Signal messenger.

The goal of the attacks is to gain remote access to computers for espionage and data theft, according to the State Special Communications Service.

CERT-UA cyber experts explained how it works:

  1. The attack begins with an attacker, well-informed about their target, sending a Microsoft Word document (e.g. "Act.doc") with an embedded macro via Signal.
  2. After opening a document and activating a macro on a computer, a hidden infection mechanism is launched, and malicious code is embedded in the system.
  3. The next step is to activate a component of the hacking framework COVENANT in the computer's memory. It uses the API of the legitimate cloud service Koofr to receive commands from the attackers.
  4. COVENANT downloads and runs a core spyware program, the BEARDSHELL backdoor, onto a computer. This program gives hackers complete control over the affected device.

The State Special Communications Service urges not to open suspicious files and not to enable macros in documents received even through instant messengers.

Hackers are using Signal to send phishing links to defense industry employees and military personnel. What to avoid
Hackers are using Signal to send phishing links to defense industry employees and military personnel. What to avoid
On the topic
Hackers are using Signal to send phishing links to defense industry employees and military personnel. What to avoid
NSDC accuses Signal of inaction in the face of Russian cyber threats
NSDC accuses Signal of inaction in the face of Russian cyber threats
On the topic
NSDC accuses Signal of inaction in the face of Russian cyber threats
Google Threat Intelligence reports that Russian hackers have invented new ways to spy on Ukrainian military accounts on Signal.
Google Threat Intelligence reports that Russian hackers have invented new ways to spy on Ukrainian military accounts on Signal.
On the topic
Google Threat Intelligence reports that Russian hackers have invented new ways to spy on Ukrainian military accounts on Signal.
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.