caution

Ehemalige Mitglieder der Conti-Ransomware-Bande halfen bei der Bekämpfung der Ukraine, sagt Google

Teilen:

Ein Blog der Threat Analysis Group beschreibt die Taktiken eines mit Russland verbundenen Bedrohungsakteurs

A cybercriminal group containing former members of the notorious Conti ransomware gang is targeting the Ukrainian government and European NGOs in the region, Google says.

The details come from a new blog post from the Threat Analysis Group (TAG), a team within Google dedicated to tracking state-sponsored cyber activity.

With the war in Ukraine having lasted more than half a year, cyber activity including hacktivism und electronic warfare has been a constant presence in the background. Now, TAG says that profit-seeking cybercriminals are becoming active in the area in greater numbers.

From April through August 2022, TAG has been following “an increasing number of financially motivated threat actors targeting Ukraine whose activities seem closely aligned with Russian government-backed attackers,” writes TAG’s Pierre-Marc Bureau. One of these state-backed actors has already been designated by CERT — Ukraine’s national Computer Emergency Response Team — as UAC-0098. But new analysis from TAG links it to Conti: a prolific global ransomware gang that shut down the Costa Rican government with a cyberattack in May.

“TAG assesses some members of UAC-0098 are former members of the Conti cybercrime group repurposing their techniques to target Ukraine”

“Based on multiple indicators, TAG assesses some members of UAC-0098 are former members of the Conti cybercrime group repurposing their techniques to target Ukraine,” Bureau writes.

The group known as UAC-0098 has previously used a banking Trojan known as IcedID to carry out ransomware attacks, but Google’s security researchers say it is now shifting to campaigns that are “both politically and financially motivated.” According to TAG’s analysis, the members of this group are using their expertise to act as initial access brokers — the hackers who first compromise a computer system and then sell off access to other actors who are interested in exploiting the target.

Recent campaigns saw the group send phishing emails to a number of organizations in the Ukrainian hospitality industry purporting to be the Cyber Police of Ukraine or, in another instance, targeting humanitarian NGOs in Italy with phishing emails sent from the hacked email account of an Indian hotel chain.

Other phishing campaigns impersonated representatives of Starlink, the satellite internet system operated by Elon Musk’s SpaceX. These emails delivered links to malware installers disguised as software required to connect to the internet through Starlink’s systems.

The Conti-linked group also exploited the Follina vulnerability in Windows systems shortly after it was first publicized in late May of this year. In this and other attacks, it is not known exactly what actions UAC-0098 has taken after systems have been compromised, TAG says.

Overall, the Google researchers point to “blurring lines between financially motivated and government backed groups in Eastern Europe,” an indicator of the way cyber threat actors often adapt their activities to align with the geopolitical interests in a given region.

But it’s not always a strategy guaranteed to win. At the start of the Ukraine invasion, Conti paid the price for openly declaring support for Russia when an anonymous individual leaked access to over a year’s worth of the group’s internal chat logs.

https://www.theverge.com/2022/9/7/23341045/former-conti-ransomware-gang-target-ukraine-google

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:49 am, Apr. 3, 2025
Wetter-Symbol 8°C
L: 7° | H: 10°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 81 %
Druck: 1019 mb
Wind: 10 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 26%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:30 am
Sonnenuntergang: 7:36 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
7° | 10°°C 0 mm 0% 12 mph 81 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 18°°C 0 mm 0% 14 mph 86 % 1021 mb 0 mm/h
Sa. Apr. 05 10:00 pm
Wetter-Symbol
7° | 17°°C 0 mm 0% 12 mph 73 % 1022 mb 0 mm/h
So. Apr. 06 10:00 pm
Wetter-Symbol
7° | 14°°C 0 mm 0% 12 mph 81 % 1025 mb 0 mm/h
Mo. Apr. 07 10:00 pm
Wetter-Symbol
6° | 14°°C 0 mm 0% 9 mph 77 % 1028 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
8° | 9°°C 0 mm 0% 10 mph 81 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
10° | 13°°C 0 mm 0% 11 mph 76 % 1019 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
15° | 18°°C 0 mm 0% 12 mph 59 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 55 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 64 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 71 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 80 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 4 mph 84 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€77,253.31
-0.91%
Ethereum(ETH)
€1,695.88
-2.13%
Fesseln(USDT)
€0.92
0.00%
XRP(XRP)
€1.91
-1.00%
Solana(SOL)
€111.17
-3.33%
USDC(USDC)
€0.92
0.01%
Dogecoin(DOGE)
€0.154215
-2.37%
Shiba Inu(SHIB)
€0.000011
0.96%
Pepe(PEPE)
€0.000006
-3.43%
Nach oben scrollen