HomeSecurityOperation Texonto: Russian hackers target Ukrainians with emails about the war

Operation Texonto: Russian hackers target Ukrainians with emails about the war

Russian hackers are targeting Ukrainian citizens with phishing emails (Operation Texonto), as part of Psychological Operations (PSYOPs). Essentially, the hackers' goal is to demoralize the victims by making them believe that Russia is winning the war (in a sense, it is a disinformation campaign ).

Operation Texonto: Russian hackers target Ukrainians with emails about the war

ESET researchers identified two distinct waves of the disinformation campaign. The first took place in November 2023 and the second in late December.

The PSYOP campaign, dubbed Operation Texonto, aims to create doubt about the progress of the conflict. The emailswarn of major impacts such as heating outages, medicine shortages and food shortages in the area.

ESET has also detected another spear phishing to steal credentials for Microsoft Office 365 accounts. Researchers believe there is a connection between the two campaigns due to similarities in the network infrastructure used.

This spear phishing campaign targeted a Ukrainian defense company in October 2023 and an EU organization in November.

See also: Organizations receive spear phishing emails with EU-related topics

Furthermore, the email server used to send the PSYOP emails to the victims was reused two weeks later to send standard spam messages to Canadian pharmacies – a popular campaign by Russian hackers.

By examining the techniques, processes, goals, and contents of the messages, researchers believe that all of these malicious campaigns are linked to a group of Russian hackers.

Operation Texonto: Russian hackers target Ukrainians

The first emails aimed at disinforming Ukrainian citizens were sent to several hundred recipients, including Ukrainian government officials , energy companies, and individual citizens.

These emails contained a variety of messages designed to sow doubt in the minds of Ukrainians about the war.

Operation Texonto phishing emails war
Operation Texonto: Russian hackers target Ukrainians with emails about the war

The emails contained PDF, which contained further disinformation messages. For example, one message said that there was a shortage of medicines and that the Ukrainian government was refusing to import medicines from Russia and Belarus.

During this first wave of PSYOPs, researchers observed the use of various domains that mimicked Ukrainian government agencies , such as the Ministry of Community Development, Land and Infrastructure of Ukraine, the Ministry of Health, and others. The hackers' goal was to lend more credibility to their emails.

Second wave of PSYOP attacks

The second wave of PSYOP attacks took place in late December 2023. It was broader as it targeted Ukrainian speakers in other European countries, as well as Ukrainian citizens.

See also: SNS Sender Malware distributes Phishing SMS via Amazon

ESET believes that several hundred people received the emails, from employees in Ukrainian government agencies to an Italian shoe manufacturer.

These emails provided Happy New Year messages that contained overtly pro-Russian content.

One of the messages even suggested that Ukrainians should amputate an arm or leg to avoid military deployment.

The emails were sent from servers operated by the attackers, such as infoattention[.]com.

Spear phishing

Researchers believe that the same Russian hackers were also behind the theft of credentials for Microsoft Office 365 accounts.

The first wave took place in October 2023, with messages to employees working at a large Ukrainian defense company.

These messages purported to come from the company's IT department, informing recipients of a scheduled inventory of unused mailboxes. Targets were asked to click on a link and log in using credentials to show that their email was active.

See also: Phishing campaign targets Microsoft Azure accounts

Researchers believe the link led to a fake Microsoft login page to steal credentials.

Russian hackers target Ukrainians
Operation Texonto: Russian hackers target Ukrainians with emails about the war

Phishing emails: Ways to protect yourself

The first and most basic practice is education. It is important to know what phishing emails look like, to be able to recognize the warning signs, such as spelling mistakes, unusual email addresses, and demands for immediate action.

Second, use a reputable email provider that offers phishing protection. These providers often have built-in tools that can identify and filter phishing emails before they reach your inbox.

It's also important to software computer up to date. Security updates can protect your computer from the latest phishing threats.

Never open attachments or click on links in emails from unknown sources. These attachments or links may contain malware that can steal your personal information.

Finally, use a manager password. This can help you maintain strong and unique passwords, which is an effective way to protect yourself from phishing attacks.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS