Ukraine says hackers abuse SyncThing tool to steal data
ID: 0a9dc7ee-4c47-511b-95c9-d96f9eed0a2c
STIX ID: report--0a9dc7ee-4c47-511b-95c9-d96f9eed0a2c
Feed Name: Bleeping Computer
CERT-UA warns of the "SickSync" campaign by UAC-0020 (Vermin) targeting Ukrainian defense forces: attackers deliver a password-protected RAR that drops a modified SyncThing binary and the SPECTR modular malware. SPECTR includes modules for screenshots, file and USB theft, credential collection from messengers and browsers, and stages stolen data under %APPDATA%\sync\Serve_Sync for exfiltration via SyncThing; interaction with SyncThing infrastructure should be treated as a compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
