The Ukrainian Security Service (SSU) announced that since the start of the war with Russia, it discovered and shut down five bot farms with over 100,000 fake accounts on social media that spread fake news.
See also: Hacked WordPress sites force visitors to launch DDoS attacks on Ukrainian sites

After a request from the Russian special services, Internet agents carried out a large‑scale information sabotage to destabilize the internal situation in Ukraine.
The network, which operated in Kharkiv, Cherkasy, Ternopil and Zakarpattia, aimed to discourage Ukrainian citizens and spread panic by distributing false information about the Russian invasion and the situation of the defenders.
See also: SunCrypt ransomware: New version with more features
According to the announcement of the SSU, the network's goal was to destabilize the sociopolitical situation in various regions, limiting the resistance of the Ukrainian militia.

The law enforcement agency in Ukraine carried out a raid on the locations hosting the bot farms and seized the following items:
· 100 GSM gateway sets
· 10,000 SIM cards for various mobile operators to cover the malicious activity
· Portable computers and computers used for the control and coordination of bots
Within the framework of the criminal procedure initiated by SBU researchers under article 110 (violation of territorial integrity and inviolability of Ukraine) of the Criminal Code of Ukraine, urgent comprehensive measures are underway for the prosecution of those involved in the attack on Ukraine. The attribution of the operation is referred to the Russian special services but so far no arrests have been made.

The SSU website was offline several times and for extended periods during the past month, as the service faced increasing challenges and had to focus on preventing a military invasion.
However, it is notable and commendable that Ukraine's cyber-agencies remain operational, at least to some extent, and publish daily announcements of their activities.
On Saturday, the Ukrainian cyber police in the Vinnytsia region announced the arrest of a man who hacked social media accounts via phishing links and used them to carry out fake ammunition raids.
Today, Ukraine's Computer Emergency Response Team announced the discovery of a phishing campaign attributed to the Russian threat group UAC-0010 (Armageddon).
See also: SonicWall code update: Not available for all devices
The campaign uses document baits that are purported to contain information about Ukrainian soldiers' casualties to spread the malware “PseudoSteel”, which allows its operators to remotely search local files and upload them to an FTP server.
All these efforts to locate and suppress Ukrainian forces signal a new era in warfare where governments can no longer ignore malicious activities in cyberspace.
Information source: bleepingcomputer.com
