Russian Phishing Uses Fake CIA Sites to Target Anti-war, Ukraine Supporters
ID: 8f30a4ca-d576-59b5-b2ff-0cacf58e39e2
STIX ID: report--8f30a4ca-d576-59b5-b2ff-0cacf58e39e2
Feed Name: HackRead
Silent Push researchers uncovered an alleged Russian intelligence phishing operation (early 2025) impersonating the CIA and various Ukraine-support organizations to harvest personal data from anti-war activists, informants, and Russian citizens; the campaign used bulletproof hosting (Nybula LLC ASN 401116), shared registrar/WHOIS artifacts, malicious domains (e.g., ciagovicu, rusvolcorpsnet, hochuzhitlife), and data exfiltration via POST requests and abused Google Forms, posing significant privacy and operational risks to targeted individuals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
