Russian hacktivists hit Ukrainian orgs with ransomware – but no ransom demands

Share:

The Ukrainian CERT (CERT-UA) has uncovered an attack campaign aimed at compromising Ukrainian organizations and irretrievably encrypting their files. To do that, they are leveraging a specific version of the Somnia ransomware that, “according to the attackers’ theoretical plan, does not provide for the possibility of data decryption.”

How the attacks unfolded

The Ukrainian cyber experts believe that the attack was effected by Russian hacktivists that go by FRwL (From Russia with Love), with help from an initial access broker (IAB).

The IAB spoofed the website of Famatech’s Advanced IP Scanner software and pointed the “Free Download” button to a Dropbox account hosting what looks like the scanner but is actually the Vidar infostealer.

 

Once installed, the infostealer connects to a predefined Mastodon user to get its configuration file (a long-standing tactic, it seems).

“It should be noted that the Vidar stealer, among other things, steals Telegram session data, which, in the absence of configured two-factor authentication and a passcode, allows unauthorized access to the victim’s account,” CERT-UA explained.

“As it turned out, the victim’s Telegram was used to transfer VPN connection configuration files (including certificates and authentication data) to users. Given the lack of two-factor authentication when establishing a VPN connection, attackers were able to gain an unauthorized connection to the corporate network.”

The team does not specify at which point the hacktivists took the attack over from the IAB, but say that, “Having gained remote access to the organization’s computer network using a VPN, the attackers conducted reconnaissance (in particular, used Netscan), launched the Cobalt Strike Beacon program, and also exfiltrated data, as evidenced by the use of the Rсlone program.”

They also used the Anydesk remote access software and the Ngrok reverse proxy.

Hacktivist continue to wage war

“FRwL (aka Z-Team), whose activity is monitored by CERT-UA under the identifier UAC-0118, took responsibility for the unauthorized intervention in the operation of automated systems and electronic computing machines of the target of the attack,” the Ukrainians say.

FRwL have been launching similar attacks against Ukrainian targets since the spring of 2022, but this time the ransomware used is different, as it uses a different algorithm (AES instead of 3DES) to encrypt files with a variety of extensions.

And, as mentioned before, this time they are apparently doing it not to “earn” money, but to disrupt the work at the target organizations.

More information and IoCs related to the attach campaing can be accessed here .

https://www.helpnetsecurity.com/2022/11/14/somnia-ransomware-ukrainian/

Russian hacktivists hit Ukrainian orgs with ransomware – but no ransom demands

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:05 pm, Jul 9, 2025
weather icon 26°C
L: 25° | H: 27°
broken clouds
Humidity: 51 %
Pressure: 1021 mb
Wind: 8 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:54 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
25° | 27°°C 0.38 mm 38% 6 mph 57 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 30°°C 0 mm 0% 7 mph 74 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 31°°C 0 mm 0% 8 mph 61 % 1021 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 11 mph 67 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 9 mph 63 % 1016 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0.38 mm 38% 6 mph 52 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 26°°C 0.06 mm 6% 2 mph 49 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 23°°C 0 mm 0% 2 mph 57 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 2 mph 68 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 74 % 1022 mb 0 mm/h
Tomorrow 7:00 am
weather icon
20° | 20°°C 0 mm 0% 3 mph 69 % 1023 mb 0 mm/h
Tomorrow 10:00 am
weather icon
24° | 24°°C 0 mm 0% 3 mph 51 % 1023 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
28° | 28°°C 0 mm 0% 4 mph 39 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,431.95
0.30%
Ethereum(ETH)
€2,272.86
2.74%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€2.03
3.39%
Solana(SOL)
€131.69
1.38%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.148221
1.61%
Shiba Inu(SHIB)
€0.000010
2.41%
Pepe(PEPE)
€0.000009
2.91%
Scroll to Top