Pro-Russian Hackers Target Critical Industries Across the Globe
ID: 72236420-9363-524b-8071-d326c39a657c
STIX ID: report--72236420-9363-524b-8071-d326c39a657c
Feed Name: GBHackers
In 2024 pro‑Russian actor SectorJ149 (aka UAC‑0050) conducted coordinated campaigns—DDoS and precision intrusions—against manufacturing, energy, and semiconductor organizations in South Korea and Ukraine, using tailored spear‑phishing (.cab VBS) to trigger hidden PowerShell that retrieves steganographically concealed Base64 payloads from Git hosts, loads PE payloads in memory, injects into legitimate processes (process hollowing), and deploys info‑stealers and RATs to exfiltrate credentials, crypto keys, and other sensitive data; the report links shared loaders and infrastructure across regions and urges stronger phishing defenses, in‑memory detection, and intelligence sharing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
