logo

Operation Texonto: Information operation targeting Ukrainian speakers in the context of the war

ID: a9d50d94-c46e-56eb-8c7c-226e8ed03b67

STIX ID: report--a9d50d94-c46e-56eb-8c7c-226e8ed03b67

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-05-01

...
...

ESET documents 'Operation Texonto', a Russian-aligned disinformation and spearphishing campaign (Nov–Dec 2023) that used lookalike Ukrainian government domains, malicious PDFs and fake Microsoft login pages to spread propaganda and steal Office 365 credentials; operators later reused infrastructure to send Canadian pharmacy spam. The report includes IoCs (domains, IPs, emails, file hashes), MITRE ATT&CK mappings, and contextual analysis of targeting and likely motives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.