Leaked Russian Cyber-Ops Training Exposes Institutional Pathways
Leaked materials reveal Russia's institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.
Sandworm UAC-0145 Uses Fake Job Interviews for Arbitrary Command Execution
CERT-UA warns of Sandworm-linked UAC-0145 targeting IT workers with fake job interviews, deploying a modified WireGuard client that executes arbitrary commands.
Sandworm Targets IT Pros With Trojanized WireGuard VPN Client
Russian threat group Sandworm targets IT professionals using fake job interviews and trojanized WireGuard VPN clients to deliver malware.
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.
Russian APTs Target Critical Infrastructure via Edge Device Exploits
US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.
Russia's Evolving Influence Ecosystem: Global Pivot & AI Integration
Russia's influence ecosystem pivots from Ukraine-centric operations to global targets, leveraging generative AI and hybrid cyber-IO tactics.
CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.
Geopolitical Exploitation of Compromised IP Cameras
Nation-states including Russia and Iran are weaponizing compromised IP cameras for battlefield intelligence and critical infrastructure surveillance.