HomeSecurityUkraine: Russian hackers Sandworm attacked Ukrinform

Ukraine: Russian hackers Sandworm attacked Ukrinform

The Ukrainian Computer Emergency Response Team (CERT-UA) has linked a devastating malware attack targeting the country's national news agency (Ukrinform) to Russian hackers Sandworm.

See also: AnyDesk: Fraudsters stole money through the application

Sandworm

According to CERT-UA experts, the attack caused some catastrophic effects on the organization's information infrastructure. However, thanks to the rapid action taken by the State Service for Special Communications and Information Protection (SSSCIP) of Ukraine, it managed to contain and detect this threat.

Ukrinform was able to maintain its operations thanks to this. At present, CERT-UA experts are helping to restore the infrastructure and continue studying the incident.

See also: Datadog: Changes RPM signing key after CircleCi attack

According to CERT-U, the recent cyberattack was likely carried out by the Sandworm group based on the methods used by its threat actors, who were linked to the Main Directorate of the General Staff of the Russian Armed Forces (GRU).

The malicious actors deployed the CaddyWiper malware on the news agency's systems with a Windows group policy (GPO), indicating that they had already infiltrated their target's network. However, despite this intrusion, they were unable to disrupt or damage any of the organization's operations.

On Wednesday, SSSCIP head Yurii Shchyhol said that since the beginning of Russia's full-scale invasion of Ukraine, they have been trying to cut off Ukrainians from learning critical information about the war and current events.

In their opponent-occupied territories, they have deliberately disabled Ukrainian television, mobile networks, and the internet to block access to factual information. In addition, they are conducting cyberattacks on national media sources for malicious purposes.

See also: MailChimp: New security breach of its employees

In April 2022, the Sandworm group made another unsuccessful attempt to damage a major Ukrainian energy supplier using the dangerous CaddyWiper malware.

Hackers attempted to cover up the traces of the Industroyer ICS malware with CaddyWiper and various data wipers developed for Linux and Solaris, such as Orcshred, Soloshred, and Awfulshred.

In March 2022, ESET security researchers made a major discovery: they discovered CaddyWiper – a data destruction malware that had been deployed to multiple Windows domains of Ukrainian organizations and was used to erase their information.

Since Russia's invasion of Ukraine in February 2022, security researchers have discovered multiple data-wiping malware targeting Ukrainian targets, including CaddyWiper, DoubleZero, HermeticWiper, IsaacWiper, WhisperKill, and WhisperGate, as well as AcidRain.

The recent ransomware attacks that hit Ukraine are reportedly attributed to the Sandworm group, an entity supported by Russian authorities.

Revealing the perpetrator in November, Microsoft announced that the Sandworm group is behind the Prestige ransomware attacks on logistics and transportation companies located in Ukraine and Poland since October 2022.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS