HomeSecurityAI: Russia's new cyberweapon in the war against Ukraine

AI: Russia's new cyberweapon in the war against Ukraine

The State Service for Special Communications and Information Protection of Ukraine (SSSCIP) has observed an increased adoption of artificial intelligence (AI) by Russian hackers for cyberattacks against the country.

Russia's AI in the war against Ukraine

“Hackers are now using it not only to create phishing messages. Some of the malware samples we analyzed show clear signs of being created with AI – and the attackers are certainly not going to stop there,” said in a report published on Wednesday.

SSSCIP recorded 3,018 cyberattack incidents during the first half of 2025. Local authorities and military entities saw an increase in attacks compared to H2 2024, while attacks targeting the government and energy sectors decreased.

See also: GitLab Security Update – Fixing Multiple Vulnerabilities

One notable attack involved the use of the WRECKSTEEL malware by UAC-0219 to target government agencies and critical infrastructure in the country. There is evidence to suggest that the data-stealing malware was developed with AI tools.

Some of the other campaigns recorded against Ukraine include:

– Phishing campaigns organized by UAC-0218 , targeting defense forces to deliver HOMESTEEL (using malicious RAR files). – Phishing campaigns organized by UAC-0226 , targeting organizations involved in the development of innovations in the defense industry, local government agencies, military units and law enforcement agencies to distribute a stealer called GIFTEDCROOK . – Phishing campaigns organized by UAC-0227 , targeting local authorities, critical infrastructure and Recruitment and Social Support Centers (TRCs and SSCs) using ClickFix tactics or SVG file attachments to distribute stealers such as Amatera Stealer and Strela Stealer.
– Phishing campaigns organized by UAC-0125 that sent emails with links to a website pretending to be ESET. The goal was to deliver a backdoor called Kalambur (or SUMBUR).

AI: Russia's new cyberweapon in the war against Ukraine

SSSCIP also observed that Russian hackers APT28 (or UAC-0001) are exploiting cross-site scripting vulnerabilities in Roundcube and Zimbra to carry out zero-click attacks.

See also: APT35: Structure, tools and espionage operations revealed

“When exploiting such vulnerabilities, attackers typically inject malicious code that, through the Roundcube or Zimbra API, gains access to credentials, contact lists, and configured filters to forward all emails to mailboxes controlled by the attackers,” SSSCIP said.

“Another method of stealing credentials, using these vulnerabilities, was to create hidden HTML blocks (visibility: hidden) with login and password input fields, where the autocomplete='on' property was set. This allowed the fields to be automatically filled with data stored in the browser, which was then exported.“.

Use of AI for effective cyber attacks and physical intrusions

The agency revealed that Russia continues to engage in hybrid warfare, synchronizing its cyber operations with physical attacks on the battlefield. The Sandworm (UAC-0002) group targets organizations in the energy and defense sectors, internet service providers, and research sectors.

AI: Russia's new cyberweapon in the war against Ukraine

Additionally, several threat groups targeting Ukraine have resorted to abusing legitimate services, such as Dropbox, Google Drive, OneDrive, Bitbucket, Cloudflare Workers, Telegram, Telegra.ph, Teletype.in, Firebase, ipfs.io, and mocky.io, to host malware or phishing pages (or turn them into a data extraction channel).

See also: Chinese hackers abuse legal tool Nezha

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“The use of legitimate online resources for malicious purposes is not a new tactic,” SSSCIP said. “However, the number of such platforms exploited by Russian hackers has steadily increased in recent times.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS