Cybersecurity researchers on Monday said they uncovered evidence of attempted attacks by a Russia-linked hacking operation targeting a Ukrainian entity in July 2021.
Broadcom-owned Symantec, in a new report published Monday, attributed the attacks to an actor tracked as Gamaredon (aka Shuckworm or Armageddon), a cyber-espionage collective known to be active since at least 2013.
In November 2021, Ukrainian intelligence agencies branded the group as a "special project" of Russia's Federal Security Service (FSB), in addition to pointing fingers at it for carrying out over 5,000 cyberattacks against public authorities and critical infrastructure located in the country.
Gamaredon attacks typically originate with phishing emails that trick the recipients into installing a custom remote access trojan called Pterodo. Symantec disclosed that, between July 14, 2021 and August 18, 2021, the actor installed several variants of the backdoor as well as deployed additional scripts and tools.
"The attack chain began with a malicious document, likely sent via a phishing email, which was opened by the user of the infected machine," the researchers said. The identity of the affected organization was not disclosed.
Towards the end of July, the adversary leveraged the implant to download and run an executable file that acted as a dropper for a VNC client before establishing connections with a remote command-and-control server under their control.
"This VNC client appears to be the ultimate payload for this attack," the researchers noted, adding the installation was followed by accessing a number of documents ranging from job descriptions to sensitive company information on the compromised machine.
Ukraine Calls Out False Flag Operation in Wiper Attacks
The findings come amidst a wave of disruptive and destructive attacks levied against Ukrainian entities by alleged Russian state-sponsored actors, resulting in the deployment of a file wiper dubbed WhisperGate, around the same time multiple websites belonging to the government were defaced.
Subsequent investigation into the malware has since revealed that the code used in the wiper was re-purposed from a faux ransomware campaign called WhiteBlackCrypt that was aimed at Russian victims in March 2021.
Interestingly, the ransomware is known to include a trident symbol — that is part of Ukraine's coat of arms — in the ransom note it displays to its victims, leading Ukraine to suspect that this may have been a false flag operation deliberately intended to blame a "fake" pro-Ukrainian group for staging an attack on their own government.
- New Hack Tools
- Hacking Tools 2019
- Hack Tools 2019
- Hacking Tools Free Download
- Hacking Tools For Games
- Hacker Hardware Tools
- Hacking Tools Windows
- Best Hacking Tools 2020
- Hacking Tools Kit
- Pentest Reporting Tools
- Termux Hacking Tools 2019
- Hacking Tools Online
- Hack Tools For Mac
- Best Hacking Tools 2020
- Pentest Reporting Tools
- Hacking Tools For Beginners
- Pentest Reporting Tools
- Pentest Tools Kali Linux
- Top Pentest Tools
- Hack Tool Apk
- Hacker Security Tools
- Hacking Tools Windows 10
- Easy Hack Tools
- Hack Tools For Windows
- Wifi Hacker Tools For Windows
- Hacks And Tools
- Hacker Tools Hardware
- Hack App
- Hacking Tools 2020
- Nsa Hack Tools
- Hacker Tools Free
- Hack Tools
- Hack Tool Apk No Root
- Nsa Hacker Tools
- What Are Hacking Tools
- Hacking Tools Name
- Hacking Tools For Mac
- Pentest Tools Website Vulnerability
- Hacker Tools Apk
- Hacker Search Tools
- Best Pentesting Tools 2018
- Hacker Tools Apk Download
- Hack Website Online Tool
- Hack Tools For Pc
- Hacker Tools Hardware
- Hacking Apps
- Computer Hacker
- Pentest Tools Url Fuzzer
- Pentest Tools Kali Linux
- Hacking Tools
- Hack Tool Apk No Root
- Hacking Tools Hardware
- Pentest Tools Kali Linux
- Pentest Tools Apk
- What Is Hacking Tools
- Termux Hacking Tools 2019
- Tools 4 Hack
- Hacking Tools Mac
- Pentest Automation Tools
- Hackrf Tools
- Hacking Tools Name
- Hacker Tools Mac
- Hacking Tools For Pc
- World No 1 Hacker Software
- Hacking Tools Online
- Pentest Tools Free
- Hacker Tools Hardware
- Hacker Tools
- Hacker Tools Github
- Hacking Tools Download
- Hacking Tools For Windows Free Download
- Blackhat Hacker Tools
- Hacker
- Blackhat Hacker Tools
- Hacker Tools Linux
- Hack Tool Apk
- Pentest Tools For Android
- Pentest Tools Framework
- Android Hack Tools Github
- Hacker Tools 2019
- How To Install Pentest Tools In Ubuntu
- Pentest Tools For Ubuntu
- Wifi Hacker Tools For Windows
- Pentest Tools Bluekeep
- Hacker Tools For Mac
- Hack Website Online Tool
- Android Hack Tools Github
- Hacks And Tools
- Hacker Tools For Ios
- Hacker Techniques Tools And Incident Handling
- Hacking Tools Name
- Hack Tool Apk No Root
- Hacking Tools Windows 10
- Hacking Tools Name
- Hacks And Tools
- Hacker Techniques Tools And Incident Handling
- Hack Apps
- Hack Tools For Windows
- Hacker Tools Windows
- Hacking Tools For Windows Free Download
- Hacking Tools Usb
- Hacker Tools For Windows
- Blackhat Hacker Tools
- Hack Tools For Pc
- Pentest Tools Github
- Hacker Tools Hardware
- Hacking Tools Windows
- Hacking Tools For Beginners
- Pentest Tools Alternative
- Hacking Tools For Windows
- Pentest Tools Alternative
- Hacking Tools For Windows 7
- Hackers Toolbox
- Hacker Tools 2019
- Nsa Hacker Tools
- Hack Tools For Games
- World No 1 Hacker Software
- Hacking Tools 2020
- Growth Hacker Tools
- Pentest Tools Url Fuzzer
- Pentest Tools Github
- Hacker Tools Hardware
- Hack Apps
- Hack Tool Apk
- Pentest Tools List
- Hack Apps
- Best Hacking Tools 2020
- Hacking Tools 2020
- Pentest Tools Url Fuzzer
- Hacking Tools For Beginners
- Wifi Hacker Tools For Windows
- Hack And Tools
- Hackrf Tools
- Free Pentest Tools For Windows
- Hacking Tools For Games
- Hack Tools Download
- Hack Tools For Windows
- Best Hacking Tools 2020
- Pentest Tools Open Source
- Pentest Tools Bluekeep
- Pentest Recon Tools
- Hacker Tools For Pc
No comments:
Post a Comment