Detect russian Attacks Targeting Ukraine: Hackers Apply the Custom Sandworm-Linked Webshell and Living-off-the-Land Tactics for Persistence
ID: 320d88f1-6959-5d13-a0f5-6129808e4d17
STIX ID: report--320d88f1-6959-5d13-a0f5-6129808e4d17
Feed Name: SOC Prime Blog
This report outlines recent Russia-linked Sandworm APT campaigns against Ukrainian organizations, describing a two-month intrusion and a separate week-long attack that relied on living-off-the-land techniques, custom webshells (e.g., Localolive), PowerShell backdoors, memory-dump scheduled tasks, and dual-use tools (including winbox64.exe) to conduct reconnaissance, credential theft, and persistent access; defenders are urged to apply relevant protections, detection rules, and threat-hunting content.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
