HomeSecurityRussian hackers behind massive spear-phishing campaign that hit Ukraine

Russian hackers behind massive spear-phishing campaign that hit Ukraine

Three Ukrainian cybersecurity agencies (Ukrainian Secret Service, Ukrainian State Police and Ukraine CERT ) issued a warning last week about a “massive” spear-phishing campaign conducted by Russian hackers against the country’s government and private organizations. This is the third massive spear-phishing campaign that the Ukrainian government has attributed to Russian-linked hackers this year.

The phishing messages sent as part of the campaign purported to come from the Kiev Patrol Police and warned recipients about problems with paying local taxes.

Read also: Phishing emails target employees with bait of returning to the office

Russian hackers - massive spear-phishing campaign - Ukraine
Russian hackers behind massive spear-phishing campaign that hit Ukraine

Specifically, the warning published by the Ukrainian Secret Service states the following: “Specialists of the Security Service of Ukraine found that in early June of this year, mass emails were sent with a different sender address. In particular, messages that appeared to come from the Kiev Patrol Police contained malicious attachments and were sent to the addresses of certain government agencies.”

According to CERT, malicious actors are sending messages on behalf of government agencies that use the following statement in their subject line: “You did not pay taxes. Information on file…”, “a criminal case has been filed against you. Information on application…”.

Additionally, the messages have a RAR file and trick victims into opening it. Upon downloading and opening the file, an EXE file with a double extension, filename.pdf.exe, is dropped onto the system.

See also: USA: Domains used by APT29 in a recent phishing campaign seized

When the recipient opens the files, they install a modified version of RemoteUtilities, a remote administration software. The software connects to C2 servers located in Russia, Germany, and the Netherlands.

massive spear-phishing campaign-Ukraine
Russian hackers behind massive spear-phishing campaign that hit Ukraine

The Security Service of Ukraine shared indicators of compromise for this attack on the “MISP-UA” platform.

CERT recommends the following:

  • Do not download encrypted or password protected files from the Internet. It is best to block the receipt of such files via email altogether.
  • Before opening email or message attachments, pay attention to the details. It is best to avoid receiving email attachments from senders whose identity you are not sure of. You should also be suspicious if the author has changed the language of communication for unknown reasons, if the subject of the letter is not typical for the author, as well as if the messages contain suspicious links or open suspicious files.
  • Restrict the ability to run executable files.
  • Periodically check the system with antivirus and update signature databases.
  • Use licensed operating systems and other software that is updated periodically .
  • Regularly back up important files.
  • Update passwords for access to important systems as often as possible and use two-factor authentication (2FA).

In February, the Ukrainian government accused a Russia-linked APT hacking group of attacking a government document management system, the System of Electronic Interaction of Executive Bodies (SEI EB).

According to Ukrainian officials, the hackers aimed to distribute malicious documents to government agencies.

massive spear-phishing campaign
Russian hackers behind massive spear-phishing campaign that hit Ukraine

Proposal: FBI-CISA: Russian hackers breached US government networks and stole data

SEI EB is used by Ukrainian government agencies for document sharing.

According to the National Security and Defense Council of Ukraine, the attackers acted to “massively infect information of public authorities.”.

At the same time, Ukraine accused anonymous Russian networks of massive attacks targeting Ukrainian security and defense sites. Ukrainian officials did not provide details about the attacks and the damage they caused.

Information source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS