Hackers are using fake drone contracts to infect Ukrainian defense enterprises
ID: 33887596-bad5-51e4-a4b0-b837f8a65040
STIX ID: report--33887596-bad5-51e4-a4b0-b837f8a65040
Feed Name: The Record from Recorded Future News
Threat Score
CERT-UA reports a targeted campaign (tracked as UAC-0180) using spearphishing emails disguised as drone procurement contracts to deliver malware families including Glueegg and Dropclue; the attackers used these loaders to deploy legitimate remote-management software (Atera) for remote access to Ukrainian defense enterprise systems, and CERT-UA notes the group continually updates its toolset.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
