The Computer Emergency Response Team of Ukraine (CERT-UA) today warned of a phishing campaign targeting private email accounts belonging to personnel of the Ukrainian armed forces.

See also: Ukraine: We need volunteer hackers to protect critical infrastructure
Accounts compromised in these attacks are then used to send additional phishing messages to victims' contacts.
The phishing messages are sent from two domains (i[.]ua-passport[.]space and id[.]bigmir[.]space), with the first attempting to imitate the free web portal i.ua that has been providing email to Ukrainians since 2008.
Phishing messages ask targets to click on an embedded link to verify contact information and avoid having their emails permanently suspended.
Attacks linked to Belarusian hacking group
The CERT-UA report attributes this ongoing phishing campaign to the UNC1151 group, which was linked by Mandiant researchers in November 2021 to the Belarusian government.
Mandiant found evidence supporting the connection between UNC1151 operators and the Belarusian military, confirming CERT-UA's assessment that the attackers are actually military cyberspies and officers of the Belarusian Ministry of Defense.
See also: Ransomware that hit Ukraine is being used as bait
“The UNC1151 group is behind these activities. Its members are officers of the Ministry of Defense of the Republic of Belarus,” CERT-UA added.
Today, the State Service for Special Communications and Information Protection of Ukraine (SSSCIP) warned Ukrainian citizens about another active phishing campaign targeting them with malicious documents.

See also: Facebook activates “lock profile” tool for users in Ukraine
A separate alert issued by Slovak cybersecurity firm ESET says cybercriminals are also impersonating humanitarian organizations in attempts to trick those who would like to donate to organizations focused on helping Ukraine during the ongoing war that was launched by Russia on Thursday morning.
Information source: bleepingcomputer.com
