HomeSecurityRussian hackers UNC5812 target Ukrainian soldiers with malware

Russian hackers UNC5812 target Ukrainian soldiers with malware

Google researchers have discovered a unique hybrid espionage/influence campaign, carried out by Russian hackers “UNC5812,” targeting newly recruited Ukrainian soldiers with malware for Windows and Android systems.

Russian hackers UNC5812

According to Google, the campaign impersonated a “Civil Defense” persona using a related website and a dedicated Telegram channel . A fake recruitment avoidance app dubbed “Sunspinner” by researchers was used to distribute the malware

The campaign targets Windows and Android devices using separate malware for each platform. Russian hackers UNC5812 can use the malware to steal data and spy on Ukrainians in real time.

Google has taken steps to prevent malicious activity.

Fake persona "Civil Defense"

Russian hackers UNC5812 did not attempt to impersonate the Civil Defense of Ukraine or any other government agency. They promoted the Civli Defense persona as a legitimate, pro-Ukrainian organization that provides Ukrainian soldiers with useful software tools and advice.

See also: Russian hackers APT29 target Zimbra and TeamCity servers

The alleged organization uses a Telegram channel and website to attract potential victims and promote narratives against Ukraine's recruitment and mobilization efforts, aiming to instill distrust and resistance among the population.

When Google discovered the campaign on September 18, 2024, the “Civil Defense” channel on Telegram already had 80,000 members.

Users who visited the Civil Defense website were taken to a download page for a malicious application, promoted as a mapping tool that can help users track recruiter locations to avoid them.

Google calls this app “Sunspinner,” and although the app features a map with markers, Google says the data is fabricated. The app’s sole purpose is to hide the installation of malware that’s happening in the background.

Windows and Android malware

The fake apps target Windows and Android systems and promise to add support for iOS and macOS as well.

On Windows, it uses Pronsis Loader, a malware loader that retrieves additional malicious payloads from the Russian hackers' UNC5812 server, including the information-stealing tool "PureStealer".

See also: Russian hackers target Ukrainian military infrastructure

PureStealer targets information stored in web browsers, such as passwords , cookies, cryptocurrency wallet details, email clients, and messaging app data.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

On Android, the downloaded APK file installs the CraxsRAT backdoor. CraxsRAT allows attackers to track the victim's location in real time, log keystrokes, record audio, retrieve contact lists, access SMS messages, and steal files and credentials.

Ukrainian soldiers with malware

In fact, the app tricks users into disabling Google Play Protect.​ Google has updated Google Play's protections to detect and block Android malware early. It has also added domains and files associated with the campaign to the 'Safe Browsing' feature in Chrome.

The use of malware for both Windows and Android systems highlights the evolving nature of cyber threats .Russian hackers UNC5812 and cybercriminals in general are constantly adapting and simultaneously using different attack vectors to achieve their goals. As a result, organizations must remain vigilant and constantly update their security protocols to protect themselves from these evolving threats.

See also: Russian GRU hackers attack critical infrastructure

In addition to stealing sensitive information, influence campaigns play a critical role in shaping public opinion and manipulating individuals’ beliefs or behaviors. In this case, the propaganda spread by Russian hackers UNC5812 could undermine trust in the Ukrainian military and sow discord. It is important for individuals to be aware of these tactics and carefully evaluate the information they read.

The full list of breach indicators related to the latest Russian hacking campaign UNC5812 is available here.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS