Recent Dr.Web cyberattack claimed by pro-Ukrainian hacktivists

Share:

A group of pro-Ukrainian hacktivists has claimed responsibility for the September breach of Russian security company Doctor Web (Dr.Web).

Dr.Web confirmed last month that its network was breached on September 14, which forced it to disconnect all internal servers and stop pushing virus database updates to customers while investigating the incident.

In a Tuesday Telegram post, DumpForums pro-Ukrainian hacktivists said they were behind the hack and gained access to Dr.Web’s development systems.

They allegedly had access to Dr.Web’s network for roughly one month, which allowed them to steal around ten terabytes of data, including client databases, from the company’s GitLab, email, Confluence, and other compromised servers.

“We managed to hack into and offload the corporate GitLab server where internal development and projects were stored, the corporate mail server, Confluence, Redmine, Jenkins, Mantis, RocketChat – systems where development was conducted and tasks were discussed,” DumpForums said.

Dr.Web allegedly hacked PostgreSQL server
Hacked PostgreSQL server (BleepingComputer)

ReliaQuest’s Threat Research Team says that DumpForums has been an online “hub for hacktivists and patriotic cyber threat actors” since at least late May 2022.

Their efforts are focused on supporting “the Ukrainian war effort against Russia” through DDoS attacks and leaking information stolen from the Russian government and private entities.

Dr.Web denies data theft claims

Today, Dr.Web published a statement in response to their claims, confirming again the September breach but saying that the attack was “promptly stopped.”

The Russian anti-malware company added that it won’t pay a ransom demand, which the attackers had since requested, and denied that customer information was stolen in the attack.

“The main goal was to demand a ransom from our company, but we are not negotiating with the attackers. At the moment, law enforcement agencies are conducting an investigation, and therefore we cannot give detailed comments so as not to interfere with the investigation,” Dr.Web said in a Wednesday Telegram post.

“The information published in Telegram is mostly untrue, user data was not affected. Neither virus database updates nor software module updates pose any security threat to our users.”

Dr.Web has yet to reply to multiple emails sent by BleepingComputer to request more information regarding the breach and DumpForums’ claims.

Dr.Web is the most recent Russian cybersecurity company that was targeted and breached in a cyberattack.

In June, pro-Ukrainian hackers Cyber Anarchy Squad breached the Russian information security firm Avanpost, claiming to have leaked 390GB of stolen data before encrypting over 400 virtual machines.

One year earlier, in June 2023, Kaspersky also disclosed that attackers infected iPhones on its network with spyware via iMessage zero-click exploits, which targeted iOS zero-day bugs as part of a campaign now known as “Operation Triangulation.”

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:51 am, Jan 31, 2025
weather icon 5°C
L: 5° | H: 6°
broken clouds
Humidity: 93 %
Pressure: 1022 mb
Wind: 7 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:40 am
Sunset: 4:47 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
5° | 6°°C 1 mm 100% 6 mph 98 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 7°°C 0 mm 0% 8 mph 94 % 1029 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 83 % 1024 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 8 mph 83 % 1026 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
6° | 10°°C 0 mm 0% 11 mph 94 % 1027 mb 0 mm/h
Today 9:00 am
weather icon
5° | 5°°C 1 mm 100% 6 mph 93 % 1022 mb 0 mm/h
Today 12:00 pm
weather icon
5° | 6°°C 0.8 mm 80% 2 mph 92 % 1022 mb 0 mm/h
Today 3:00 pm
weather icon
6° | 7°°C 0 mm 0% 4 mph 88 % 1023 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 93 % 1026 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 98 % 1028 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 5 mph 94 % 1028 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 94 % 1029 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 90 % 1029 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,249.13
-0.83%
Ethereum(ETH)
€3,117.70
1.56%
XRP(XRP)
€2.95
-1.17%
Tether(USDT)
€0.96
-0.01%
Solana(SOL)
€226.54
-1.59%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.314700
-0.96%
Shiba Inu(SHIB)
€0.000018
0.34%
Pepe(PEPE)
€0.000013
0.21%
Scroll to Top