In 2023, Ukraine was the target of 60% of Russian phishing attacks.
Google's Threat Analysis Group (TAG) has been monitoring and preventing Russian government-backed cyberattacks against Ukraine's critical infrastructure in 2023.

Google reports that from January to March 2023, Ukraine received approximately 60% of phishing attacks originating from Russia, making it the most targeted country.
In most cases, the campaign's goals include intelligence gathering, operational disruption, and leaking sensitive data through Telegram channels dedicated to causing informational damage in Ukraine.
See also: VMware fixes vRealize bug that allows attackers to execute code as root
Groups operating in Ukraine
During the first quarter of the year, Google's Threat Analysis Team (TAG) identified three groups of Russian and Belarusian hackers who had carried out significant attacks on targets in Ukraine.
The first threat actor is called Sandworm and is detected by Google as “FrozenBarents.” It has been targeting the energy sector across Europe since November 2022, with a major incident involving the Caspian Pipeline Consortium (CPC).

Recently, the Sandworm group has launched multiple phishing campaigns using fake “Ukroboronprom” websites against Ukrainian defense industry workers, users of the Ukr.net platform, or even Ukrainian Telegram channels.

The threat group also creates multiple online personas to spread false information on YouTube and Telegram , often leaking portions of data stolen through phishing or network intrusions

Another highly active Russian threat actor is the APT28 group, identified by Google as “FrozenLake.”.
Between February and March 2023, APT28 sent multiple large waves of phishing emails targeting Ukrainians. The hackers also used reflected cross-site scripting (XSS) on Ukrainian government websites to redirect visitors to phishing pages.

This week, a joint statement from the UK NCSC, FBI, NSA and CISA warned that APT28 is hacking Cisco Routers to install customized malware.
The third threat actor mentioned in Google's report is "Pushcha, believed to be based in Belarus, a country that is politically favorable to the Kremlin.
Pushcha recently launched campaigns targeting Ukrainian webmail providers, such as “i.ua” and “meta.ua”, attempting to steal users’ credentials by creating fake websites

See also: Lazarus hackers: Linked to 3CX attack and targeting Linux users with fake job offers
State-sponsored disinformation
Google's report also highlights cases of misinformation on its platforms, such as YouTube and Blogger.
“In the first quarter of 2023, TAG observed a coordinated IO campaign by actors affiliated with the Internet Research Agency (IRA) creating content on Google products like YouTube, including commenting and upvoting videos,” the Google TAG report states.
IRA (Glavset) is a Russian company linked to the owner of the Wagner Group, Y. Prigozhin, that engages in online propaganda and influence on behalf of Russian political interests.
According to Google, it identified and blocked accounts linked to the IRA from producing content on YouTube Shorts to promote certain “news” stories about the war in Ukraine to Russian viewers.
All websites associated with these campaigns have been added to Google's "Safe Browsing" block list, while affected Gmail and Workspace users have been notified via malicious communication alerts .
Information source: bleepingcomputer.com
