About past, present and future of Ukraine

Search mobile

Main War GRU hackers target Ukrainian research institutions

War

GRU hackers target Ukrainian research institutions

422
GRU hackers target Ukrainian research institutions

Share this article

Researchers report a new wave of cyber espionage aimed at Ukrainian scientific and research institutions, linked to the APT28 group, also known as Fancy Bear or BlueDelta, associated with Russian military intelligence (GRU), as reported by CERT-UA

CERT-UA, Ukraine's computer security incident response team, noted that in early July of the current year, the group UAC-0063 used known malware programs Hatvibe and Cherryspy. These programs had previously been used in a cyber espionage campaign targeting a government agency in Ukraine.

Researchers associate UAC-0063 with APT28 based on medium-confidence analysis. APT28 is known for its actions against countries and organizations, including numerous attacks on Ukraine and its partners.

Hackers operating on behalf of APT28 employed various tactics, including exploiting a vulnerability in HFS, a web server used for file sharing over HTTP. This allowed them to install the Hatvibe backdoor and initiate cyber espionage.

In addition to Ukraine, institutions in other countries, such as Mongolia, Kazakhstan, Kyrgyzstan, Israel, and India, have also been targeted by UAC-0063. Documents related to attacks on the Armenian Ministry of Defense found in the VirusTotal repository confirm the global reach of the group's activities.

 

by CERT-UA

 

The Odessa Journal
more articles

Top article

The Ministry of Defense has signed a contract for the construction of a service center for repairing drones in Ukraine
War

The Ministry of Defense has signed a contract ...

Dmytro Kuleba: Ukraine and Croatia have agreed to use Croatian ports for exporting Ukrainian grain
Business

Dmytro Kuleba: Ukraine and Croatia have agree ...

New sanctions: Defence industry, political parties and individuals linked to oligarchs
Business

New sanctions: Defence industry, political pa ...

Volodymyr Zelensky: We are preparing for the next Ramstein meeting, we expect solidly grounded decisions to meet the prospects on the battlefield
War

Volodymyr Zelensky: We are preparing for the ...