HomeSecuritySandworm hackers targeted 20 critical infrastructure facilities in Ukraine

Sandworm hackers targeted 20 critical infrastructure facilities in Ukraine

According to Ukraine's Computer Emergency Response Team (CERT-UA), Russian hackers Sandworm targeted about 20 critical infrastructure facilities in the country with the aim of disrupting their operation.

hackers Sandworm Ukraine critical infrastructure

The Sandworm hackers are believed to be linked to the Main Directorate of the General Staff of the Russian Armed Forces (GRU) and carry out cyberespionage attacks . They are also known as BlackEnergy, Seashell Blizzard, Voodoo Bear and APT44.

CERT-UA reports that in March 2024, Russian hackers conducted attacks to disrupt information and communication systems at energy, water, and heating suppliers in 10 regions of Ukraine. In some cases, Sandworm hackers were able to penetrate the targets' networks by infecting the supply chain to deliver compromised or vulnerable software.

See also: Sandworm group carries out attacks as hacktivists

The hacking group also used old and new malware to gain access and move around the network.

CERT-UA experts have confirmed the breach of at least three “supply chains.” The Ukrainian cybersecurity notes that the Sandworm hackers’ breaches were made easier by poor security practices implemented by the targets (e.g., lack of network segmentation and inadequate defenses at the software vendor level).

From March 7 to March 15, 2024, CERT-UA participated in extensive cyber counterattack operations, which included updating affected businesses, removing malware, and enhancing security.

According to the research, the Sandworm hackers mainly used the following malware to attack Ukraine's critical infrastructure:

QUEUESEED/IcyWell/Kapeka: Backdoor that targets Windows machines, collects basic system information and executes commands from a remote server. Communications are secured via HTTPS and data is encrypted using RSA and AES.

BIASBOAT (new): This is a new Linux variant of QUEUESEED. It appears as an encrypted file server and works in parallel with LOADGRIP.

LOADGRIP (new): Another Linux variant of QUEUESEED used to inject payload into processes using ptrace API. The payload is usually encrypted and the decryption key is derived from a fixed and machine-specific ID.

GOSSIPFLOW : A Windows malware for setting up tunneling using the Yamux multiplexer library. It provides SOCKS5 proxy functionality for data extraction and secure communication with the command and control server.

See also: Russian Sandworm hackers use new Kapeka backdoor

Additionally, CERT-UA identified other malicious tools used by the Sandworm hackers, such as the Weevly webshell, Regeorg.Neo, Pitvotnacci and Chisel tunnelers, LibProcessHider, JuicyPotatoNG and RottenPotatoNG.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Sandworm hackers targeted 20 critical infrastructure facilities in Ukraine
Sandworm hackers targeted 20 critical infrastructure facilities in Ukraine

Attackers used these tools to maintain persistence, hide malicious processes, and escalate privileges on compromised systems.

Protection of critical infrastructure of Ukraine

Fortunately, there are some methods to combat the attacks. First of all, it is important to use antivirus software and security programs.

Additionally, regularly backing up important data and files can prevent information loss in the event of an attack.

See also: MITRE: Hackers breached systems through Ivanti vulnerabilities

Educating users on how to recognize and avoid suspicious emails and links is also an effective method for preventing malware installation .

Updating systems and applications is also essential to correct security gaps that hackers.

Finally, collaboration with information systems security experts is essential to strengthen cybersecurity.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS