logo

Who Is Behind Pro-Ukrainian Cyberattacks on Iran?

ID: 4691b367-5acc-53d6-984b-9402e13de7fa

STIX ID: report--4691b367-5acc-53d6-984b-9402e13de7fa

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-10

Date Updated: 2026-04-21

Author: Alex Haynes

...
...

The report describes Nebula, a pro‑Ukrainian hacktivist group that has conducted DDoS and intrusion operations against Russian targets and unexpectedly breached Iran's Raykasoft in October, claiming to have exfiltrated and dropped over 10TB of medical data and destroyed servers; the report also documents technical artifacts (Meterpreter shells, a likely LimeNet source IP and a Cobalt Strike beacon) and assesses this as an opportunistic, but concerning, deviation from other Ukrainian-aligned groups' targeting norms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.