Russian hackers have targeted organizations in Ukraine, with the aim of disconnecting sensitive data and maintaining continuous access to compromised networks. According to a report by Symantec and Carbon Black Threat Hunter Team, the activity targeted a large service provider for two months and a local government entity for one week.
See also: British Army hit by cyberattack

The attacks primarily used living-off-the-land (LotL) and dual-use tools, along with minimal malware, to reduce digital footprints and remain invisible for extended periods. The attackers gained access to the service provider by deploying web shells on publicly accessible servers, likely exploiting unpatched vulnerabilities.
One of the web shells used was Localolive, which has previously been flagged by Microsoft as being used by a subgroup of the Russian Sandworm connection as part of a multi-year campaign codenamed BadPilot. Localolive is designed to facilitate the delivery of subsequent payloads such as Chisel, plink, and rsockstun, and has been in use since at least late 2021. The first signs of malicious activity targeting the service provider date back to June 27, 2025, with the attackers exploiting their foothold to drop a web shell and conduct reconnaissance.
They were found executing PowerShell commands to exclude the machine's Downloads from Microsoft Defender Antivirus scans and to set up a scheduled task to perform a memory dump every 30 minutes. Over the following weeks, the attackers carried out various actions, such as:
See also: NoName057(16) attacks a public works procurement platform

- Saving a copy of the registry hive to a file named 1.log
- Dropping additional web shells
- Use of the web shell to enumerate all files in the user directory
- Execution of a command to enumerate all running processes that start with “kee,” likely targeting the KeePass password storage vault
- Enumeration of all active user sessions on a second machine
- Running executables named “service.exe” and “cloud.exe” located in the Downloads folder
- Execution of reconnaissance commands on a third machine and execution of memory dumping using the Microsoft Windows Resource Leak Diagnostic (RDRLeakDiag) tool
- Modification of the registry to allow RDP connections
- Execution of a PowerShell command to retrieve information about Windows configuration on a fourth machine
- Running RDPclip to access the clipboard in remote desktop connections
- Installation of OpenSSH to facilitate remote access
- Execution of a PowerShell command to allow TCP traffic on port 22 for the OpenSSH server
- Creating a scheduled task to execute an unknown PowerShell backdoor (link.ps1) every 30 minutes using a domain account
- Execution of an unknown Python script
- Deployment of a legitimate MikroTik router management application (“winbox64.exe”) in the Downloads folder.
The presence of “winbox64.exe” was also documented by CERT-UA in April 2024 in connection with a Sandworm campaign targeting energy, water, and heating suppliers in Ukraine. Symantec and Carbon Black said they could not find evidence linking the attacks to Sandworm, but noted that the activity “appeared to be of Russian origin.”
See also: AI: Russia's new cyberweapon in the war against Ukraine

The cybersecurity company revealed that the attacks were characterized by the development of numerous PowerShell backdoors and suspicious executables that are likely malicious software, although none of these items have been obtained for analysis.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
