Hackers posing as Ukraine’s Security Service infect 100 govt PCs

Share:

Attackers impersonating the Security Service of Ukraine (SSU) have used malicious spam emails to target and compromise systems belonging to the country’s government agencies.

On Monday, the Computer Emergency Response Team of Ukraine (CERT-UA) disclosed that the attackers successfully infected over 100 computers with AnonVNC malware.

Some samples were signed using the code signing certificate of what looks like a Chinese company (Shenzhen Variable Engine E-commerce Co Ltd).

“Good afternoon, in connection with the comprehensive inspection of a number of organizations, I am asking you to submit to the Main Directorate of the SBU at the address 01601, Kyiv 1, str. Malopodvalna, 16, list of requested documents until August 15, 2024. Download the official request: Dokumenty.zip,” the malicious emails read, linking to an attachment pretending to be a document list required by the SSU.

These attacks began over a month ago, around July 12, with emails pushing hyperlinks to a Documents.zip archive that would instead download a Windows installer MSI file from gbshost[.]net designed to deploy the malware.

While CERT-UA doesn’t provide an exact description of the malware’s capabilities, it said that it enabled the threat group tracked as UAC-0198 to access the compromised computers covertly.

“CERT-UA has identified more than 100 affected computers, in particular, among central and local government bodies,” CERT-UA said.

“Note that related cyber attacks have been carried out since at least July 2024 and may have a broader geography.”

Ukraine under attack

​Last month, cybersecurity company Dragos revealed that a late January 2024 cyberattack used Russian-linked FrostyGoop malware to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures.

FrostyGoop is the ninth ICS malware discovered in the wild, with many linked to Russian threat groups. Mandiant found CosmicEnergy, and ESET spotted Industroyer2, which Sandworm hackers used in a failed attack on a Ukrainian energy provider.

In April, CERT-UA also disclosed that the notorious Sandworm Russian military hacking group targeted, and in some cases breached, 20 energy, water, and heating critical infrastructure organizations in Ukraine.

In December, Sandworm also hacked into and wiped thousands of systems on Kyivstar’s network, Ukraine’s largest telecommunications service provider. In all, as CERT-UA revealed in October, they breached the networks of 11 Ukrainian telecom service providers since May 2023.

The Main Intelligence Directorate (GUR) of Ukraine’s Ministry of Defense also claimed it hacked the Russian Ministry of Defense in March after previously claiming responsibility for breaches of the Russian Center for Space Hydrometeorology, the Russian Federal Air Transport Agency, and the Russian Federal Taxation Service.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:19 pm, Jan 22, 2025
weather icon 4°C
L: 2° | H: 5°
broken clouds
Humidity: 87 %
Pressure: 1003 mb
Wind: 7 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
2° | 5°°C 1 mm 100% 18 mph 90 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
5° | 11°°C 1 mm 100% 25 mph 89 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
2° | 5°°C 1 mm 100% 6 mph 96 % 1013 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
1° | 7°°C 0 mm 0% 16 mph 95 % 1013 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
4° | 9°°C 1 mm 100% 26 mph 92 % 996 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 4°°C 0 mm 0% 4 mph 84 % 1003 mb 0 mm/h
Tomorrow 3:00 am
weather icon
3° | 3°°C 0 mm 0% 5 mph 90 % 1004 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 7 mph 87 % 1005 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 0 mm 0% 9 mph 83 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
8° | 8°°C 0 mm 0% 16 mph 76 % 1000 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
8° | 8°°C 1 mm 100% 18 mph 71 % 999 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
6° | 6°°C 0.8 mm 80% 16 mph 72 % 1002 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 11 mph 75 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,969.99
-2.28%
Ethereum(ETH)
€3,132.50
-2.03%
XRP(XRP)
€3.05
-0.16%
Tether(USDT)
€0.96
-0.05%
Solana(SOL)
€252.98
4.07%
Dogecoin(DOGE)
€0.345479
-4.05%
USDC(USDC)
€0.96
0.01%
Shiba Inu(SHIB)
€0.000019
-2.75%
Pepe(PEPE)
€0.000014
-3.41%
Peanut the Squirrel(PNUT)
€0.348999
-2.58%
Scroll to Top