Suspected Russian hacking, influence operations take aim at Ukrainian military recruiting
ID: 6efa5f5d-2407-57c6-a8a2-83151be0fc0a
STIX ID: report--6efa5f5d-2407-57c6-a8a2-83151be0fc0a
Feed Name: CyberScoop
Google's Threat Analysis Group and Mandiant describe a suspected Russian-linked group (UNC5812) running a hybrid espionage and influence operation targeting potential Ukrainian conscripts: malware for Windows and Android is distributed via a Telegram persona called 'Civil Defense', the site instructs victims to disable Google Play Protect, and the operation amplifies anti-mobilization narratives via promoted posts and sharing of user-submitted content; researchers first observed activity in September and shared findings with Ukrainian authorities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
