Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors
ID: 94f7b6ab-b90e-5078-a0f1-e7354a940a44
STIX ID: report--94f7b6ab-b90e-5078-a0f1-e7354a940a44
Feed Name: cybersecurityNews.com
Ukraine-linked actors are running a targeted cyber-espionage campaign against Russian aerospace and defence suppliers and prime contractors, using spear-phishing lures (job offers, invites, contract updates) to deliver a small DLL loader that pulls a second-stage script and injects a final payload into trusted processes. The tailored malware includes modules for email scraping, document theft, credential capture, and a simple C2 command loop to switch between silent exfiltration and interactive shell access; persistence is maintained via scheduled tasks and hijacked update tools to minimize detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
