logo

Ukraine says hackers abuse SyncThing tool to steal data

ID: 0a9dc7ee-4c47-511b-95c9-d96f9eed0a2c

STIX ID: report--0a9dc7ee-4c47-511b-95c9-d96f9eed0a2c

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-06-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CERT-UA warns of the "SickSync" campaign by UAC-0020 (Vermin) targeting Ukrainian defense forces: attackers deliver a password-protected RAR that drops a modified SyncThing binary and the SPECTR modular malware. SPECTR includes modules for screenshots, file and USB theft, credential collection from messengers and browsers, and stages stolen data under %APPDATA%\sync\Serve_Sync for exfiltration via SyncThing; interaction with SyncThing infrastructure should be treated as a compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.