logo

Ukraine Military Targeted With Russian APT PowerShell Attack

ID: 72432719-69c0-5d2a-a52b-a3288f569563

STIX ID: report--72432719-69c0-5d2a-a52b-a3288f569563

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-02-01

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

A Russian APT linked to Shuckworm/STEADY#URSA has launched a targeted campaign against the Ukrainian military using a newly observed SUBTLE-PAWS PowerShell backdoor distributed via phishing-compressed archives and removable USB drives; the malware uses off-disk PowerShell stagers, registry-based persistence, multiple obfuscation methods (Base64, XOR, encoding/splitting), and adaptive C2 via Telegram, DNS and HTTP. Securonix highlights the campaign's evasive TTPs and recommends mitigations including user education, strict USB/device control policies, Sysmon and PowerShell logging, application whitelisting, enhanced email filtering, and EDR solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.