Cyber ​​attacks in Ukraine by Russian hacker group "Gamaredon"

B2B Cyber ​​Security ShortNews

Share post

Even before the current cyber attacks on Ukraine and its KRITIS, there were attacks that were evaluated by Palo Alto Networks Unit 42. According to their findings, the state-supported Russian hacker group "Gamaredon" is behind the attacks.

Cybersecurity analysts from Palo Alto Networks' Unit42 team have just released new information about Gamaredon's activities. This is a hacking group that the Ukrainian SSU (Sluzhba bespeky Ukrajiny - Ukrainian Internal Security Service) recently reported is being run by 5 Russian FSB officers.

Russian hacker group “Gamaredon”

Unit 42 security analysts found evidence that Gamaredon was targeting the Ukrainian government and other organizations and even a Western government agency in Ukraine over the past 3 months as part of widespread attacks.

The research identifies:

  • • 700 dangerous domains
  • • 100 malware samples
  • • 215 dangerous IP addresses

While monitoring this activity, Unit 42 observed an attempt to attack a Western government agency in Ukraine on January 19, 2022. In this attempt, instead of emailing a downloader directly to their target, the attackers instead used an internal job search and employment service in Ukraine. The attackers searched for an active job posting, uploaded a Word document marked as a resume, and submitted it to a western government agency via the job search platform. Given the strides and precise malware delivery associated with this campaign, this appears to have been a deliberate, deliberate attempt by Gamaredon to target this Western government organization in Ukraine. An analysis is also available on the homepage.

More at PaloAltoNetworks.com

 


About Palo Alto Networks

Palo Alto Networks, the global leader in cybersecurity solutions, is shaping the cloud-based future with technologies that transform the way people and businesses work. Our mission is to be the preferred cybersecurity partner and protect our digital way of life. We help you address the world's biggest security challenges with continuous innovation leveraging the latest breakthroughs in artificial intelligence, analytics, automation, and orchestration. By delivering an integrated platform and empowering a growing ecosystem of partners, we are the leaders in protecting tens of thousands of businesses across clouds, networks and mobile devices. Our vision is a world where every day is safer than the one before.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more