Tag: ukraine
-
Russian military hackers pose as recruiters to target Ukrainian IT workers
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. First seen on therecord.media Jump to article: therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers
-
New Zealand sanctions Russian hackers, propaganda groups over Ukraine war
New Zealand announced new sanctions on Russian hackers, technology companies and Kremlin-linked organizations over their roles in supporting Moscow’s war against Ukraine. First seen on therecord.media Jump to article: therecord.media/new-zealand-russian-hackers-sanctions
-
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take. First seen on therecord.media Jump to article: therecord.media/interview-jim-hockenhull-uk-defence-intelligence-russia-ukraine
-
Russian businesses erase Durov-linked products after ‘terrorist’ designation
The designation, announced last week, came a day after Russia’s Federal Security Service (FSB) charged Durov with aiding terrorist activity and said it would seek to place him on an international wanted list. The agency accused Telegram of failing to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
Finland to disconnect fiber-optic link to Russia as lease expires
Finland stopped power transmissions with Russia at the start of the war in Ukraine, and two related telecom connections will stop at the end of this year, authorities said. First seen on therecord.media Jump to article: therecord.media/finland-russia-fiber-optic-disconnection
-
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing…
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed…
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed Laundry Bear, sends half-click phishing emails that require a victim only to open or preview the message. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
-
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/
-
North Korean IT Worker Scams Fueling Ukrainian Invasion
Leaked Payment Server Data Lets Researchers Trace Money Flows. Salaries paid to North Korean IT workers end up converted to ammunition used against Ukraine, warns new research based on a trove of leaked payment server data. North Korea has for years smuggled remote and contract IT workers onto Western payrolls. First seen on govinfosecurity.com Jump…
-
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Tags: advisory, cctv, cybersecurity, intelligence, Internet, military, russia, service, spy, ukraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military…
-
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia’s First seen on…
-
Zelensky appoints Ukraine’s acting security service chief as acting defense minister
Yevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine’s new acting defense minister. First seen on therecord.media Jump to article: therecord.media/ukraine-acting-defense-minister-yevhenii-khmara
-
Ukrainians rally against dismissal of tech-minded defense minister Fedorov
Ukraine President Volodymyr Zelensky dismissed Defense Minister Mykhailo Fedorov, who championed the push to integrate drone technology and digital innovation into the military. First seen on therecord.media Jump to article: therecord.media/ukraine-fedorov-drones-dismissal
-
Sandworm hackers have a CAPTCHA trick for Ukrainians
Rather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers. First seen on therecord.media Jump to article: therecord.media/ukraine-sandworm-hacks-captcha-powershell
-
Treasury sanctions First VPN Service, others for abetting ransomware gangs
The designations hit 1VPNS, its alleged Ukrainian administrator and a Belarusian who allegedly sold “cryptors” to disguise ransomware and other malware. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-sanctions-first-vpn-ransomware/
-
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. First seen on therecord.media Jump to article: therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
-
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. First seen on therecord.media Jump to article: therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
-
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans.The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian First…
-
VPN service favored by ransomware groups is sanctioned by US
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware “cryptors.” First seen on therecord.media Jump to article: therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups
-
Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charges
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hacker-extradited-ukraine-guilty/
-
Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations
An alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. Extradited from Ukraine after his…
-
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
The fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protect themselves. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/businesses-wartime-cybersecurity-gameplans
-
Ukrainian media outlets now among ‘priority targets’ for Russian hackers
A top Ukrainian security official described two previously unreported attacks on TV media organizations and said Russia has ramped up hacking activities against the industry. First seen on therecord.media Jump to article: therecord.media/ukraine-media-organizations-priority-hacking-targets-russia
-
Gamaredon group expands malware arsenal in ongoing Ukraine cyberattacks
First seen on scworld.com Jump to article: www.scworld.com/brief/gamaredon-group-expands-malware-arsenal-in-ongoing-ukraine-cyberattacks
-
XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t
Police arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most influential Russian-language cybercrime forum of the past decade. Europol, which coordinated the operation under the…
-
Kremlin Expands AI-Backed Campaigns Across Europe, US
GenAI Is Accelerating Propaganda, Planning and Content Creation. Google Threat Intelligence Group says Russia is expanding AI-enabled influence operations beyond Ukraine to target the European Union and NATO, relying on proxy networks, hacktivists and coordinated cyber campaigns to undermine Western cohesion while reducing attribution. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/google-kremlin-expands-ai-backed-campaigns-across-europe-us-a-32120

