logo

Pro-Russian Hackers Target Critical Industries Across the Globe

ID: 72236420-9363-524b-8071-d326c39a657c

STIX ID: report--72236420-9363-524b-8071-d326c39a657c

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2025-09-15

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

In 2024 pro‑Russian actor SectorJ149 (aka UAC‑0050) conducted coordinated campaigns—DDoS and precision intrusions—against manufacturing, energy, and semiconductor organizations in South Korea and Ukraine, using tailored spear‑phishing (.cab VBS) to trigger hidden PowerShell that retrieves steganographically concealed Base64 payloads from Git hosts, loads PE payloads in memory, injects into legitimate processes (process hollowing), and deploys info‑stealers and RATs to exfiltrate credentials, crypto keys, and other sensitive data; the report links shared loaders and infrastructure across regions and urges stronger phishing defenses, in‑memory detection, and intelligence sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.