Hackers posing as Ukraine’s Security Service infect 100 govt PCs

Share:

Attackers impersonating the Security Service of Ukraine (SSU) have used malicious spam emails to target and compromise systems belonging to the country’s government agencies.

On Monday, the Computer Emergency Response Team of Ukraine (CERT-UA) disclosed that the attackers successfully infected over 100 computers with AnonVNC malware.

Some samples were signed using the code signing certificate of what looks like a Chinese company (Shenzhen Variable Engine E-commerce Co Ltd).

“Good afternoon, in connection with the comprehensive inspection of a number of organizations, I am asking you to submit to the Main Directorate of the SBU at the address 01601, Kyiv 1, str. Malopodvalna, 16, list of requested documents until August 15, 2024. Download the official request: Dokumenty.zip,” the malicious emails read, linking to an attachment pretending to be a document list required by the SSU.

These attacks began over a month ago, around July 12, with emails pushing hyperlinks to a Documents.zip archive that would instead download a Windows installer MSI file from gbshost[.]net designed to deploy the malware.

While CERT-UA doesn’t provide an exact description of the malware’s capabilities, it said that it enabled the threat group tracked as UAC-0198 to access the compromised computers covertly.

“CERT-UA has identified more than 100 affected computers, in particular, among central and local government bodies,” CERT-UA said.

“Note that related cyber attacks have been carried out since at least July 2024 and may have a broader geography.”

Ukraine under attack

​Last month, cybersecurity company Dragos revealed that a late January 2024 cyberattack used Russian-linked FrostyGoop malware to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures.

FrostyGoop is the ninth ICS malware discovered in the wild, with many linked to Russian threat groups. Mandiant found CosmicEnergy, and ESET spotted Industroyer2, which Sandworm hackers used in a failed attack on a Ukrainian energy provider.

In April, CERT-UA also disclosed that the notorious Sandworm Russian military hacking group targeted, and in some cases breached, 20 energy, water, and heating critical infrastructure organizations in Ukraine.

In December, Sandworm also hacked into and wiped thousands of systems on Kyivstar’s network, Ukraine’s largest telecommunications service provider. In all, as CERT-UA revealed in October, they breached the networks of 11 Ukrainian telecom service providers since May 2023.

The Main Intelligence Directorate (GUR) of Ukraine’s Ministry of Defense also claimed it hacked the Russian Ministry of Defense in March after previously claiming responsibility for breaches of the Russian Center for Space Hydrometeorology, the Russian Federal Air Transport Agency, and the Russian Federal Taxation Service.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:18 am, Jun 22, 2025
weather icon 24°C
L: 23° | H: 25°
broken clouds
Humidity: 55 %
Pressure: 1013 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 72%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 25°°C 0.25 mm 25% 16 mph 61 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 80 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 14 mph 80 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 28°°C 0.21 mm 21% 10 mph 85 % 1014 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
16° | 20°°C 1 mm 100% 12 mph 95 % 1015 mb 0 mm/h
Today 4:00 am
weather icon
18° | 22°°C 0.25 mm 25% 9 mph 60 % 1013 mb 0 mm/h
Today 7:00 am
weather icon
17° | 19°°C 0 mm 0% 10 mph 61 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
22° | 22°°C 0 mm 0% 12 mph 49 % 1014 mb 0 mm/h
Today 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 14 mph 34 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 24°°C 0 mm 0% 16 mph 41 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 51 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 10 mph 59 % 1013 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 11 mph 71 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€88,603.45
-1.06%
Ethereum(ETH)
€1,982.75
-4.81%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.79
-2.85%
Solana(SOL)
€117.29
-3.31%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.134158
-4.73%
Shiba Inu(SHIB)
€0.000010
-3.86%
Pepe(PEPE)
€0.000008
-5.54%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top