Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers exploit flaws in apache http server to deploy linuxsys cryptocurrency miner

How biodegradable microplastics affect agroecosystems

Lovable will become a unicorn in the $200 million Series A just eight months after its release

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CERT-UA reports cyberattack targeting Ukrainian provincial systems with WreckSteel malware
Identity

CERT-UA reports cyberattack targeting Ukrainian provincial systems with WreckSteel malware

userBy userApril 4, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 4, 2025Ravi LakshmananCritical Infrastructure/Malware

Cyberattacks targeting Ukrainians

The Ukrainian Computer Emergency Response Team (CERT-UA) has revealed that more than three cyberattacks have been recorded against the country’s national control bodies and critical infrastructure facilities with the aim of stealing sensitive data.

According to the campaign, the campaign uses compromised email accounts to send phishing messages that contain links pointing to legitimate services such as DropMefiles and Google Drive. In some cases, the links are embedded in PDF attachments.

Digital Missib attempted to induce a false sense of urgency by claiming that Ukrainian government agencies would cut their payroll, urging recipients to click on the link to view a list of affected employees.

Cybersecurity

Accessing these links will lead to downloading a Visual Basic Script (VBS) loader designed to get and run PowerShell scripts that can harvest specific sets of extensions and files that capture screenshots.

Activities attributed to threat clusters tracked as UAC-0219 have been ongoing since at least fall 2024, and early iterations are said to be ongoing using legitimate image editor software to achieve your goals using EXE binaries, VBS Steelers, and legitimate image editor software called IRFANVIEW.

CERT-UA gave Monica Rex Steel to its VBS loader and PowerShell malware. The attacks were not attributed to any country.

Cyberattacks targeting Ukrainians

The development warned that Kaspersky warned that a threat actor known as Headmare would target several Russian entities with malware that could handle instructions issued by operators on command and control (C2) servers, and download and run additional payloads like Meshagent.

Suppliers and developers of Russian energy, industrial and electronic component organizations were also found on the receivers of phishing attacks attached by unicorns with threat actor codenames that dropped a VBS Trojan horse designed to suck up files and images from infected hosts.

Cybersecurity

Later last month, Seqrite Labs revealed that Russian academic, government, aerospace and defense-related networks are being targeted by weaponized decoy documents, possibly sent via phishing emails, as part of a campaign called Operation Holokill. The attack is believed to have started around December 2024.

Malware Layer PDF

The activity uses social engineering tricks to disguise malware-equipped PDFs as research invitations, and tempt government communicatures that entice unsuspecting users to trigger an attack chain.

“The threat entity provides malicious RAR files containing .NET malware droppers. This removes more decoy-based PDFs with Goran-based shellcode loaders and legal OneDrive applications as well as final cobalt strike payloads.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRussia-Ukraine War: List of Major Events, Day 1,135 | News of the Russian-Ukraine War
Next Article Midjourney releases the V7. This is the first new AI image model in nearly a year
user
  • Website

Related Posts

Hackers exploit flaws in apache http server to deploy linuxsys cryptocurrency miner

July 17, 2025

Europol destroys Hacktivist Group linked to DDOS attacks against Ukraine

July 17, 2025

What security leaders need to know in 2025

July 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers exploit flaws in apache http server to deploy linuxsys cryptocurrency miner

How biodegradable microplastics affect agroecosystems

Lovable will become a unicorn in the $200 million Series A just eight months after its release

Europol destroys Hacktivist Group linked to DDOS attacks against Ukraine

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.