Hackers posing as Ukraine’s Security Service infect 100 govt PCs

Teilen:

Attackers impersonating the Security Service of Ukraine (SSU) have used malicious spam emails to target and compromise systems belonging to the country’s government agencies.

On Monday, the Computer Emergency Response Team of Ukraine (CERT-UA) disclosed that the attackers successfully infected over 100 computers with AnonVNC malware.

Some samples were signed using the code signing certificate of what looks like a Chinese company (Shenzhen Variable Engine E-commerce Co Ltd).

“Good afternoon, in connection with the comprehensive inspection of a number of organizations, I am asking you to submit to the Main Directorate of the SBU at the address 01601, Kyiv 1, str. Malopodvalna, 16, list of requested documents until August 15, 2024. Download the official request: Dokumenty.zip,” the malicious emails read, linking to an attachment pretending to be a document list required by the SSU.

These attacks began over a month ago, around July 12, with emails pushing hyperlinks to a Documents.zip archive that would instead download a Windows installer MSI file from gbshost[.]net designed to deploy the malware.

While CERT-UA doesn’t provide an exact description of the malware’s capabilities, it said that it enabled the threat group tracked as UAC-0198 to access the compromised computers covertly.

“CERT-UA has identified more than 100 affected computers, in particular, among central and local government bodies,” CERT-UA said.

“Note that related cyber attacks have been carried out since at least July 2024 and may have a broader geography.”

Ukraine under attack

​Last month, cybersecurity company Dragos revealed that a late January 2024 cyberattack used Russian-linked FrostyGoop malware to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures.

FrostyGoop is the ninth ICS malware discovered in the wild, with many linked to Russian threat groups. Mandiant found CosmicEnergy, and ESET spotted Industroyer2, which Sandworm hackers used in a failed attack on a Ukrainian energy provider.

In April, CERT-UA also disclosed that the notorious Sandworm Russian military hacking group targeted, and in some cases breached, 20 energy, water, and heating critical infrastructure organizations in Ukraine.

In December, Sandworm also hacked into and wiped thousands of systems on Kyivstar’s network, Ukraine’s largest telecommunications service provider. In all, as CERT-UA revealed in October, they breached the networks of 11 Ukrainian telecom service providers since May 2023.

The Main Intelligence Directorate (GUR) of Ukraine’s Ministry of Defense also claimed it hacked the Russian Ministry of Defense in March after previously claiming responsibility for breaches of the Russian Center for Space Hydrometeorology, the Russian Federal Air Transport Agency, and the Russian Federal Taxation Service.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:06 am, Juni 22, 2025
Wetter-Symbol 24°C
L: 23° | H: 25°
broken clouds
Luftfeuchtigkeit: 55 %
Druck: 1013 mb
Wind: 6 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 72%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
23° | 25°°C 0.25 mm 25% 16 mph 61 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 80 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 14 mph 80 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0.21 mm 21% 10 mph 85 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
16° | 20°°C 1 mm 100% 12 mph 95 % 1015 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 22°°C 0.25 mm 25% 9 mph 59 % 1013 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 10 mph 61 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 49 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 14 mph 34 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 16 mph 41 % 1012 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 14 mph 51 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 10 mph 59 % 1013 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 71 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,637.29
-1.08%
Ethereum(ETH)
€1,992.64
-4.50%
Fesseln(USDT)
€0.87
0.02%
XRP(XRP)
€1.79
-2.65%
Solana(SOL)
€117.63
-3.19%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.134000
-4.89%
Shiba Inu(SHIB)
€0.000010
-3.59%
Pepe(PEPE)
€0.000008
-5.61%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen