According to Ukraine's Computer Emergency Response Team (CERT-UA), Russian hackers Sandworm targeted about 20 critical infrastructure facilities in the country with the aim of disrupting their operation.

The Sandworm hackers are believed to be linked to the Main Directorate of the General Staff of the Russian Armed Forces (GRU) and carry out cyberespionage attacks . They are also known as BlackEnergy, Seashell Blizzard, Voodoo Bear and APT44.
CERT-UA reports that in March 2024, Russian hackers conducted attacks to disrupt information and communication systems at energy, water, and heating suppliers in 10 regions of Ukraine. In some cases, Sandworm hackers were able to penetrate the targets' networks by infecting the supply chain to deliver compromised or vulnerable software.
See also: Sandworm group carries out attacks as hacktivists
The hacking group also used old and new malware to gain access and move around the network.
CERT-UA experts have confirmed the breach of at least three “supply chains.” The Ukrainian cybersecurity notes that the Sandworm hackers’ breaches were made easier by poor security practices implemented by the targets (e.g., lack of network segmentation and inadequate defenses at the software vendor level).
From March 7 to March 15, 2024, CERT-UA participated in extensive cyber counterattack operations, which included updating affected businesses, removing malware, and enhancing security.
According to the research, the Sandworm hackers mainly used the following malware to attack Ukraine's critical infrastructure:
QUEUESEED/IcyWell/Kapeka: Backdoor that targets Windows machines, collects basic system information and executes commands from a remote server. Communications are secured via HTTPS and data is encrypted using RSA and AES.
BIASBOAT (new): This is a new Linux variant of QUEUESEED. It appears as an encrypted file server and works in parallel with LOADGRIP.
LOADGRIP (new): Another Linux variant of QUEUESEED used to inject payload into processes using ptrace API. The payload is usually encrypted and the decryption key is derived from a fixed and machine-specific ID.
GOSSIPFLOW : A Windows malware for setting up tunneling using the Yamux multiplexer library. It provides SOCKS5 proxy functionality for data extraction and secure communication with the command and control server.
See also: Russian Sandworm hackers use new Kapeka backdoor
Additionally, CERT-UA identified other malicious tools used by the Sandworm hackers, such as the Weevly webshell, Regeorg.Neo, Pitvotnacci and Chisel tunnelers, LibProcessHider, JuicyPotatoNG and RottenPotatoNG.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Attackers used these tools to maintain persistence, hide malicious processes, and escalate privileges on compromised systems.
Protection of critical infrastructure of Ukraine
Fortunately, there are some methods to combat the attacks. First of all, it is important to use antivirus software and security programs.
Additionally, regularly backing up important data and files can prevent information loss in the event of an attack.
See also: MITRE: Hackers breached systems through Ivanti vulnerabilities
Educating users on how to recognize and avoid suspicious emails and links is also an effective method for preventing malware installation .
Updating systems and applications is also essential to correct security gaps that hackers.
Finally, collaboration with information systems security experts is essential to strengthen cybersecurity.
Source: www.bleepingcomputer.com
