Poland says Russian state hackers , linked to the Russian military intelligence agency (GRU), have been targeting Polish government networks in the past week.

According to data from the country's Computer Security Incident Response Team and CERT Polska, Russian hackers attacked using phishing techniques.
The phishing emails attempted to trick recipients into clicking on an embedded link that supposedly would provide them with access to more information about a “mysterious Ukrainian woman” who was selling “used underwear” to “higher authorities in Poland and Ukraine.”
See also: Megazord Ransomware attacks healthcare and government entities
The link took victims to a page that downloaded a ZIP file. This contained a malicious executable file, disguised as a JPG image file, and two hidden files: a DLL and a .BAT script.
If the target opens the executable, it loads the DLL via DLL side loading and executes a hidden script. The script displays a photo of a woman in a swimsuit in the Microsoft Edge, while simultaneously downloading a CMD file and changing its extension to JPG.
According to the Polish researchers, the script ultimately collects information about the target's computer (IP address and list of files in selected folders).
The attacks have raised concerns among Polish officials, who fear that sensitive information. The government has taken immediate steps to secure its networks and systems, but the full extent of the damage is not yet known.
See also: LockBit ransomware leaks government contractor data

The recent attacks by Russian hackers on Polish government institutions are a stark reminder of the growing threat of state-sponsored hacking and highlight the need for stronger cybersecurity. As technology continues to advance, it is vital for governments to prioritize the protection of their networks and systems in order to safeguard sensitive information and maintain national security. These attacks also highlight the importance of international cooperation in addressing cyber and protecting against malicious actors. It is therefore important for all countries to work together to strengthen their cyber defenses and prevent future incidents.
Russian hackers APT28
Russian hackers APT28 have targeted many other countries, in addition to Poland. Since their emergence in the mid-2000s, they have been carrying out cyberattacks . The hackers were linked to the GRU Military Unit 26165 in 2018.
See also: BlackTech targets government sectors with Deuterbear
A week ago, NATO and the European Union, with international partners, also officially condemned a long-running espionage by hackers APT28 against several European countries, including Germany and the Czech Republic.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
