Advertisement
Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine
Russian state-sponsored group 'Laundry Bear' exploits a Zimbra zero-day via 'half-click' phishing, targeting US and Ukrainian entities for credential theft and backdoor…
Russian Intelligence Hijacks IP Cameras to Track NATO Logistics
Russian intelligence services are hijacking security cameras to monitor military logistics and troop movements throughout NATO member states and Ukraine.
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.
Russian Intelligence Steals Messaging Credentials via SMS Lures
Ukraine and the FBI expose a long-running Russian intelligence campaign using fake support messages to compromise officials' messaging accounts.
Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.
Russian APT Gamaredon Upgrades UAC-0010 Malware Arsenal
Analysis of Russian APT Gamaredon's (UAC-0010) upgraded arsenal, featuring stealthier Pterodo malware loading and volatile C2 infrastructure rotation.
Advertisement
Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign
Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.
Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations
Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.
CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.
CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine
Russia-linked actors Earth Dahu and UAC-0226 exploit the CVE-2025-8088 WinRAR path traversal flaw to deploy info-stealers against Ukrainian organizations.
Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.
GREYVIBE: Russian Actor's AI-Powered Cyberattacks Target Ukraine
Analysis of GREYVIBE, a newly discovered Russian-linked threat actor utilizing AI-powered techniques to target Ukrainian entities since August 2025.
GreyVibe Actor Leverages AI Lures to Target Ukrainian Entities
Russian threat cluster GreyVibe uses ChatGPT and Gemini to automate highly targeted phishing lures and deploy custom malware against Ukrainian targets.
Ghostwriter Targets Ukraine Government with Prometheus Phishing
Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…
Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike
Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.
UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware
UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.
AgingFly Malware: Credential Theft Operations Against Ukraine
Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…
APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware
APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.
APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit
Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…