Russia-linked espionage campaign targeting Ukraine using Starlink and charity lures
ID: 11b39f24-fc43-5acf-a3c4-dba6a8643ea1
STIX ID: report--11b39f24-fc43-5acf-a3c4-dba6a8643ea1
Feed Name: The Record from Recorded Future News
Researchers observed a Russia-linked APT known as Laundry Bear (Void Blizzard) conducting a February cyber-espionage campaign against Ukrainian organizations using documents impersonating a Ukrainian charity and Starlink verification materials to deliver DrillApp spyware. The backdoor, executed via Microsoft Edge, can upload/download files and capture audio, webcam images, and screen recordings; attackers are leveraging browser capabilities and public text-sharing services to evade detection, and analysts characterize the malware as early-stage development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
