logo

Russian Phishing Uses Fake CIA Sites to Target Anti-war, Ukraine Supporters

ID: 8f30a4ca-d576-59b5-b2ff-0cacf58e39e2

STIX ID: report--8f30a4ca-d576-59b5-b2ff-0cacf58e39e2

Feed Name: HackRead

Threat Score
85/100

Date Published: 2025-03-28

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Silent Push researchers uncovered an alleged Russian intelligence phishing operation (early 2025) impersonating the CIA and various Ukraine-support organizations to harvest personal data from anti-war activists, informants, and Russian citizens; the campaign used bulletproof hosting (Nybula LLC ASN 401116), shared registrar/WHOIS artifacts, malicious domains (e.g., ciagovicu, rusvolcorpsnet, hochuzhitlife), and data exfiltration via POST requests and abused Google Forms, posing significant privacy and operational risks to targeted individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.