Skip to main content
← All Articles

Tag

#Ukraine

21 articles

Advertisement

Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine
HIGH
Threat Intel

Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine

Russian state-sponsored group 'Laundry Bear' exploits a Zimbra zero-day via 'half-click' phishing, targeting US and Ukrainian entities for credential theft and backdoor…

Runtime Rebel Intel
4 min read · Jul 24, 2026
Russian Intelligence Hijacks IP Cameras to Track NATO Logistics
HIGH
Threat Intel

Russian Intelligence Hijacks IP Cameras to Track NATO Logistics

Russian intelligence services are hijacking security cameras to monitor military logistics and troop movements throughout NATO member states and Ukraine.

Runtime Rebel Intel
4 min read · Jul 20, 2026
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
HIGH
Threat Intel

UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware

Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.

Runtime Rebel Intel
4 min read · Jul 19, 2026
Russian Intelligence Steals Messaging Credentials via SMS Lures
HIGH
Threat Intel

Russian Intelligence Steals Messaging Credentials via SMS Lures

Ukraine and the FBI expose a long-running Russian intelligence campaign using fake support messages to compromise officials' messaging accounts.

Runtime Rebel Intel
4 min read · Jun 27, 2026
HIGH
Threat Intel

Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit

Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.

Runtime Rebel Intel
13 min read · Jun 26, 2026
Russian APT Gamaredon Upgrades UAC-0010 Malware Arsenal
HIGH
Threat Intel

Russian APT Gamaredon Upgrades UAC-0010 Malware Arsenal

Analysis of Russian APT Gamaredon's (UAC-0010) upgraded arsenal, featuring stealthier Pterodo malware loading and volatile C2 infrastructure rotation.

Runtime Rebel Intel
3 min read · Jun 26, 2026

Advertisement

HIGH
Threat Intel

Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign

Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.

Runtime Rebel Intel
4 min read · Jun 26, 2026
Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations
HIGH
Threat Intel

Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations

Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.

Runtime Rebel Intel
4 min read · Jun 26, 2026
CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
HIGH
Threat Intel

CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw

Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.

Runtime Rebel Intel
3 min read · Jun 9, 2026
CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine
HIGH
Threat Intel

CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine

Russia-linked actors Earth Dahu and UAC-0226 exploit the CVE-2025-8088 WinRAR path traversal flaw to deploy info-stealers against Ukrainian organizations.

Runtime Rebel Intel
3 min read · Jun 9, 2026
Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
HIGH
Threat Intel

Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine

Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.

Runtime Rebel Intel
3 min read · Jun 2, 2026
GREYVIBE: Russian Actor's AI-Powered Cyberattacks Target Ukraine
HIGH
Threat Intel

GREYVIBE: Russian Actor's AI-Powered Cyberattacks Target Ukraine

Analysis of GREYVIBE, a newly discovered Russian-linked threat actor utilizing AI-powered techniques to target Ukrainian entities since August 2025.

Runtime Rebel Intel
4 min read · May 29, 2026
HIGH
Threat Intel

GreyVibe Actor Leverages AI Lures to Target Ukrainian Entities

Russian threat cluster GreyVibe uses ChatGPT and Gemini to automate highly targeted phishing lures and deploy custom malware against Ukrainian targets.

Runtime Rebel Intel
4 min read · May 29, 2026
Ghostwriter Targets Ukraine Government with Prometheus Phishing
HIGH
Threat Intel

Ghostwriter Targets Ukraine Government with Prometheus Phishing

Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.

Runtime Rebel Intel
4 min read · May 22, 2026
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
HIGH
Threat Intel

FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing

Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…

Runtime Rebel Intel
4 min read · May 14, 2026
Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike
HIGH
Threat Intel

Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike

Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.

Runtime Rebel Intel
4 min read · May 14, 2026
UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware
HIGH
Threat Intel

UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware

UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.

Runtime Rebel Intel
3 min read · Apr 16, 2026
HIGH
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…

Runtime Rebel Intel
5 min read · Apr 16, 2026
APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware
HIGH
Threat Intel

APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware

APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Threat Intel

APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit

Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.

Runtime Rebel Intel
3 min read · Mar 19, 2026
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
HIGH
Threat Intel

DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users

DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…

Runtime Rebel Intel
4 min read · Mar 19, 2026