HomeSecurityPhishing attacks target countries helping Ukrainian refugees

Phishing attacks target countries helping Ukrainian refugees

A phishing campaign is targeting European Commission staff providing logistical support to Ukrainian refugees.

See also: An ongoing phishing campaign targets Citibank customers

phishing

According to US cybersecurity firm Proofpoint, the attackers are using "possibly compromised" email accounts of members of the Ukrainian armed forces to deliver the phishing message.

The researchers said that the phishing attacks they observed only targeted European government entities and added that, for now, they cannot attribute the attacks to any specific hacking group.

“Proofpoint has identified a potential nation-state-sponsored phishing campaign using a possible compromised email of a member of the Ukrainian armed forces to target European Commission staff involved in managing the logistics of refugees fleeing Ukraine,” Proofpoint researchers said.

The email included a malicious macro attachment that attempted to download a Lua-based malware called SunSeed, a malware downloader that can be used to deliver second-stage payloads to compromised devices.

See also: Ukraine links phishing targeting armed forces to Belarusian hackers

However, based on the infection chain, researchers said the campaign is being monitored as it is likely related to phishing attacks that took place in July 2021 and are linked to the Ghostwriter group (also tracked as TA445 or UNC1151).

The Ghostwriter group was linked by Mandiant security researchers to the Belarusian government.

phishing

Since Russia invaded Ukraine seven days ago, this group has already been linked to other attacks against Ukrainians.

For example, the Computer Emergency Response Team of Ukraine (CERT-UA) warned that Ghostwriter operators are attempting to hack the private email accounts of Ukrainian military personnel and “related individuals” to deliver phishing emails to their contacts.

See also: eBike phishing websites promote scams through Google Ads

On Monday, Facebook also removed accounts used by Ghostwriter to target the accounts of Ukrainian officials and military personnel on its platform. It also said it had blocked phishing domains used to attempt to compromise Ukrainian users' accounts.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS