logo

Suspected Russian hacking, influence operations take aim at Ukrainian military recruiting

ID: 6efa5f5d-2407-57c6-a8a2-83151be0fc0a

STIX ID: report--6efa5f5d-2407-57c6-a8a2-83151be0fc0a

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2024-10-28

Date Updated: 2026-04-21

Author: Tim Starks

...
...

Google's Threat Analysis Group and Mandiant describe a suspected Russian-linked group (UNC5812) running a hybrid espionage and influence operation targeting potential Ukrainian conscripts: malware for Windows and Android is distributed via a Telegram persona called 'Civil Defense', the site instructs victims to disable Google Play Protect, and the operation amplifies anti-mobilization narratives via promoted posts and sharing of user-submitted content; researchers first observed activity in September and shared findings with Ukrainian authorities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.