🚀💳 Trustee Plus - більше ніж криптогаманець з європейською платіжною карткою. Спробуй 👉

Since February, attackers have intensified cyberattacks and are hunting the military, law enforcement officers, and military-tech developers — State Service for Special Communications

Experts from the State Special Communications Service are warning developers of innovations in the military sector, as well as military personnel, law enforcement officers, and employees of local governments, especially those located along the country’s eastern border, about the intensification of cyberattacks.

Leave a comment
Since February, attackers have intensified cyberattacks and are hunting the military, law enforcement officers, and military-tech developers — State Service for Special Communications

Experts from the State Special Communications Service are warning developers of innovations in the military sector, as well as military personnel, law enforcement officers, and employees of local governments, especially those located along the country’s eastern border, about the intensification of cyberattacks.

The Ukrainian government’s computer emergency response team CERT-UA reports that attackers are sending emails from compromised accounts, including through a web interface.

The letter from cybercriminals contains attachments in the form of XLS documents with macros (extension «.xlsm»). The names/topics of the malicious attachments are disguised as issues of demining the territory, administrative fines, UAV production, compensation for destroyed property, etc. The «malware» is contained in the form of base64-encoded strings among the cells of the Excel spreadsheet. The mentioned macro provides conversion (decoding) of base64-encoded strings into executable files, their saving to the computer without extension and subsequent launch.

As of April 2025, the State Service for Special Communications reports two types of software tools for implementing cyber threats:

  1. A .NET program whose resources contain a PowerShell script, which is functionally a reverse shell borrowed from the public GitHub repository PSSW100AVB.
  2. Classified as GIFTEDCROOK, a C/C++ stealer program that, among other things, provides access to the databases of Internet browsers Chrome, Edge, Firefox (cookies, history, saved authentication data), their archiving using the PowerShell cmdlet Compress-Archive, and subsequent exfiltration to Telegram.

The described cyber threat cluster is tracked by the identifier UAC-0226.

Cybersecurity workers are warning system administrators and asking them to separately check the availability, completeness, and depth of mail and web server logs.

Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
5 tips that can protect your business from cyberattacks
5 tips that can protect your business from cyberattacks
On the topic
5 tips that can protect your business from cyberattacks
Ukrzaliznytsia promises to return previously purchased tickets lost after cyberattack to users. Here's what you need to do
Ukrzaliznytsia promises to refund users previously purchased tickets lost after cyberattack. Here’s what you need to do
On the topic
Ukrzaliznytsia promises to refund users previously purchased tickets lost after cyberattack. Here’s what you need to do
"Information will have to be collected bit by bit." Ukrzaliznytsia told how long it might take to fully restore all services after a large-scale Russian cyberattack
«Information will have to be collected bit by bit.» Ukrzaliznytsia told how long it might take to fully restore all services after a large-scale Russian cyberattack
On the topic
«Information will have to be collected bit by bit.» Ukrzaliznytsia told how long it might take to fully restore all services after a large-scale Russian cyberattack
Підключай Megogo зі знижками за акційними тарифами.

від 99 гривень на місяць

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.